Short Answer
No. Clients cannot directly edit or customize the Start of Authority (SOA) record through the Rebel account dashboard, domain manager, or Plesk hosting zone file editors.
All SOA records across our domain management and web hosting platforms are centrally managed at our server infrastructure level.
Why Are SOA Records Locked at the Infrastructure Level?
The Start of Authority (SOA) record is the foundational administrative record for every DNS zone file. It contains critical system values—such as serial numbers, server synchronization timers, and administrative contact parameters—that direct how DNS servers communicate across the global internet.
We manage SOA records globally at the server cluster level for two critical reasons:
- Ensuring DNS Cluster Stability & Sync: Our DNS infrastructure operates on a highly available, globally distributed network of nameservers. Managing SOA parameters centrally ensures that DNS updates, IP changes, and website routing propagate instantly across all secondary nodes without sync failures or replication delays.
- Preventing Accidental Outages: Incorrect SOA timing parameters or mismatched serial numbers can cause external internet resolvers to drop cached zone data, resulting in widespread website downtime and email delivery failures. Locking SOA templates eliminates the risk of accidental DNS misconfigurations.
Understanding Your Domain's SOA Parameters
For transparency, every domain utilizing Rebel default nameservers uses the following standard, high-availability SOA configuration:
| SOA Field | Default Value | Purpose / Description |
| Primary Nameserver | dns.rebel.ca | Identifies the primary authoritative server managing your DNS zone. |
| Hostmaster Email | hostmaster.rebel.ca | The administrative contact address for the DNS system (. replaces the @ symbol). |
| Serial Number | (Dynamic YYYYMMDDNN) | Automatically increments every time you edit a DNS record (A, CNAME, MX, TXT) so secondary servers know to pull updates. |
| Refresh Rate | 86400 (24 Hours) | Determines how frequently secondary nameservers check the primary server for updates. |
| Retry Rate | 7200 (2 Hours) | Sets the wait time before secondary servers attempt to re-establish connection if a refresh check fails. |
| Expire Limit | 604200 (7 Days) | Specifies how long secondary servers serve cached data during a primary server disconnect. |
| Minimum TTL | 3600 (1 Hour) | The standard cache duration for negative responses (e.g., NXDOMAIN). |
Notice a Warning on MXToolbox or Third-Party DNS Scanners?
If you run a domain health check on tools like MXToolbox or DNSViz, you may occasionally see a suggestion regarding the SOA Expire timer:
"SOA Expire Value out of recommended range — Expire is recommended to be between 1209600 (14 days) and 2419200 (28 days)."
What does this mean for your domain?
This is a general informational recommendation offered by monitoring tools, rather than a technical issue or operational failure.
- Why It’s Flagged: Many third-party DNS scanners compare domain configurations against broad reference guidelines that suggest keeping cached DNS records active for 2 to 4 weeks during extended network disruptions.
- How Our System Protects You: At Rebel, our infrastructure utilizes a highly available, globally distributed DNS cluster. Our standard 7-day (604,200 seconds) expiration window strikes an optimal balance—ensuring secondary servers hold valid data during temporary internet disruptions, while allowing routine DNS updates to sync smoothly across the network.
Rest assured: Your domain settings are fully functional. This informational check has no negative impact on your website accessibility, email performance, or DNS reliability, and no changes are necessary.
Need Custom SOA Values for Enterprise Compliance?
If your organization has strict corporate compliance policies, security audit mandates, or specialized internal tools that require custom SOA values (such as custom Refresh or Expire timers):
- Delegate Nameservers to a Fully Customizable DNS Provider: You can point your domain's Name Servers (NS) to an external enterprise DNS provider that supports user-defined SOA editing, such as Amazon Route 53, IBM NS1, or Azure DNS. (Note: Cloudflare also manages SOA records at the infrastructure level and does not permit custom SOA edits).
- Keep Your Hosting & Registration with Rebel: You can easily manage your custom SOA parameters in your external DNS console while continuing to maintain your domain registration, Plesk web hosting, and email services seamlessly with Rebel.
Comments
0 comments
Please sign in to leave a comment.