Using DNSCMD to delete NS records (HELP)

Posted on 2013-01-02
Last Modified: 2013-01-04
After recently demoting a domain controller, I noticed that the NS record for this server was still listed in our forward and reverse lookup zones.

Upon closer inspection, I’m noticing other old NS records for DC’s that were demoted years ago as well.

From what I am reading, it looks like the tool dnscmd can be used to delete the records across the DC’s on our WAN.

Below is my site info:

Forward lookup zone =
Reverse lookup zone = 192.168.1.x
DC name = dc1

Below is the command syntax for using dnscmd / recorddelete:

dnscmd /recorddelete ZoneName NodeName RRType RRData

Using the info above, I am unsure if I am interpreting everything correctly – and I am unsure of what info is used in place of RRData.

I could use some direction in getting my syntax down before running the command – any help would be greatly appreciated.
Question by:acmi
  • 8
  • 2
  • 2
  • +2
LVL 57

Expert Comment

by:Mike Kline
ID: 38738327
RRData is the IP address

RRType is the record type - NS in your case.


LVL 18

Expert Comment

by:Sarang Tinguria
ID: 38738329
refer below link it has all the steps to be taken care after unsuccessful DC demotion
If your DC's were demoted gracefuly then skip the metadata part

Metadata cleanup:

Author Comment

ID: 38738389
Okay, looks like I need to be more clear.

The info below is an example of my site info:

Forward lookup zone =
DC name = dc1

The command syntax to delete records from DNS is below:

dnscmd /recorddelete ZoneName NodeName RRType RRData

Using the info above, I need help in applying my info to the syntax of the command correctly.  I need to know what info should be listed in the () below:

dnscmd /recorddelete ZoneName ( NodeName (dc1) RRType (NS) RRData (?)


dnscmd / recorddelete dc1 NS ?
LVL 18

Expert Comment

by:Sarang Tinguria
ID: 38738413
dnscmd /recorddelete DC1 NS
LVL 26

Assisted Solution

by:Leon Fester
Leon Fester earned 500 total points
ID: 38739220
Do you have standard alone DNS zones or are the AD-integrated.
if AD-integrated then I think you're making your life unneccessarily difficult.

You can use the DNS gui and delete the record from your local DNS server and it will replicate to the other DNS servers.
GUI can also be used to delete from remote servers either logon directly or connect via the local GUI, just right-click the DNS root and select connect to "Connect to DNS server" and select the remote server.

You don't provide enough information for us to contruct the complete DNSCMD command for you.
Here is a good reference with examples.
e.g. dnscmd /recorddelete @ NS /f

Author Comment

ID: 38740333
Hello Sarang_Tinguria,

Thank you for your reply.  

DC1 in my example is actually the old DNS server that I want to delete.  I was under the impression that the NodeName was the server name who’s records we want to delete (please let me know if I am wrong).

With this in mind, is the line below correct?

dnscmd /recorddelete DC1 NS

Author Comment

ID: 38740578
Hello DVT_Localboy

Our zones are AD integrated.

However, I would prefer getting the command correct rather than searching through DNS for old records – as they can be found in several areas.  It seems like the command route would be more thorough.

Example – I’m finding old records in the area below as well as almost every subdirectory within the root.\_msdcs\domains\blabla\_tcp

In regards to not providing enough info to construct the complete command, what info is missing?

We have the ZoneName (
We have the NodeName (dc1 – I’m understanding the NodeName to mean the name of the DC we are trying to remove – let me know if this is incorrect)
We have the RRType (NS)
Where I am unsure is the RRData info.

Is the RRData the same as the fully qualified name of the record I want to delete –

If so, the line below should work – let me know if this is incorrect.

dnscmd /recorddelete DC1 NS
3 Use Cases for Connected Systems

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, testing some more, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us.


Author Comment

ID: 38740673
I believe I have the command correct (in some respect) in my two replies above, as I am now prompted with a “Are you sure you want to delete record” message.

But when I choose “yes” I receive the following error: Command failed: DNS_ERROR_NAME_DOES_NOT_EXIST

So something is still off...

Author Comment

ID: 38740716
Never mind, I figured it out.  I'll follow up when I've finished up.

Accepted Solution

acmi earned 0 total points
ID: 38741609
Okay, here’s the deal if anyone stumbles onto this looking for a solution:

First, the command string below from Microsoft is something that I was never able to get to work.

-      dnscmd /recorddelete ZoneName NodeName RRType RRData

Second, the command string from Brian ( does work when you know what info to plug in where.

-      dnscmd /recorddelete ZoneName @ RRType RecordInfo

ZoneName = the domain from where the record is to be deleted
RRType = the type of record (A, NS, etc.)
RecordInfo = the record to be deleted (FQN)

Apply this to my example:

-      dnscmd /recorddelete @ NS


So, in response to a posting above, the information needed to construct the complete DNSCMD was indeed supplied in the original post as well as in the subsequent thread.  You only need to know the record you want to delete, the record type and the domain from where you want to delete.

Author Comment

ID: 38744262
I've requested that this question be closed as follows:

Accepted answer: 0 points for acmi's comment #a38741609

for the following reason:

the other postings did not provide the solution I had asked for - some where wrong altogether.
LVL 26

Expert Comment

ID: 38741669
I'd have to say that dvt_localboy got it right in #38739220.

His example:
dnscmd /recorddelete @ NS /f
The command that worked for you:
dnscmd /recorddelete @ NS
That's pretty dead-on, if you ask me.  The only difference is the /f switch, which simply specifies that you don't want to be prompted for confirmation.

Author Comment

ID: 38741757
He also said that I had not provided enough info to construct the command – which was not correct (bad info) – everything was there.  I wasted a lot of time trying to figure out what could be missing (aggravating) – and there was no reply when I asked what was missing.  I’m sure I would have gotten a reply at some point, but it would have been wrong as all the info that was needed was posted.

And throwing an example without applying it to my issue was not very helpful as well (I included my info for a reason).

If anyone were looking for the same solution, my solution would be the most helpful from the tread.
LVL 26

Expert Comment

by:Leon Fester
ID: 38742960
LMFAO - You reference the links I provided, but I didn't help to resolve this problem.

I wasted a lot of time trying to figure out what could be missing (aggravating)

– Considering your attitute, I'm glad I didn't waste my time either.

and there was no reply when I asked what was missing.

- I don't sit on EE all day baby feeding people information. I have a life and job in real life too.

Hope you have lots of fun with those points you saved yourself, looks like you need them more than me.
LVL 26

Expert Comment

ID: 38744263
I think I'll put this in a moderator's hands, which will hopefully get it resolved to everyone's satisfaction.

Mod: There's a dispute about whether a posted answer was correct.  See previous posts for details.

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
DHCP DNS Set up 4 60
Office 365 SSO and Shared Devices 6 41
Way to setup network drive share permanently mapped to server 3 47
Password change 3 21
One of the most often confused topics in the area DNS is the idea of GLUE records. Specifically, what they are, when they are needed, when they are provided, and how they are created. First, WHAT IS GLUE? To understand GLUE, you must first under…
Occasionally you run into the website or two that will not resolve properly using your own DNS servers.  Some people simply set up global forwarders for their DNS server.  I don’t recommend doing this because it can cause problems resolving addresse…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now