Authoritative anycast DNS on a network we run ourselves.
Anycast presence at locations that matter, served from AS54098. DNSSEC and IPv6 by default, with fast TTL changes when you need them.
- anycast · authoritative
- DNSSEC · IPv6 · AXFR / IXFR
- AS54098 · IXP-anchored nodes
- API · web · zone file import
Anycast DNS, in plain terms.
Authoritative DNS hosted on AS54098 with anycast presence at the locations where your traffic actually originates. Multiple nodes share a single set of IPs, so resolvers land on whichever node is closest by BGP — same answer, shorter path. Direct peering at AS6939 Hurricane Electric and AS3257 GTT plus IXP presence means the resolver path is short for most of the global routing table.
DNSSEC signing is supported and we will help with the parent delegation. IPv6 nameservers are not optional. Zone editing is straightforward — API, web, or zone file import — and TTL changes propagate as fast as your old TTL allows. AXFR and IXFR for teams who want to keep a hidden primary; we will be a secondary or take over as primary, whichever fits.
Monitoring is run by the same NOC that watches the rest of our gear. If a node goes quiet, traffic shifts before you notice.
Common triggers for this engagement.
- 01Your current DNS provider had a bad day and you are shopping
- 02You need DNSSEC and IPv6 on day one, not as a paid add-on
- 03You want a hidden primary with us as authoritative secondaries
- 04You want to know who is actually answering your queries
Questions teams ask before signing.
Can I keep my current registrar?
Yes. Registrar and DNS hosting are separate decisions. Point your NS records at our nameservers and you are done — we will help with the DS records if you turn on DNSSEC.
How many anycast nodes do you operate?
Enough to anchor at the internet exchanges and metros that matter for the routing table, with on-net peering through AS6939 and AS3257. We can share specifics under NDA — the honest answer is 'sized for resilience, not for a billboard.'
Do you support hidden primary setups?
Yes. We will sit as authoritative secondaries against your hidden primary using AXFR / IXFR, signed and rate-limited. Or we can be the primary and accept changes via API. Both are common.
What is the minimum useful node count?
The public footprint is anchored at the internet exchanges where we already peer through AS6939 and AS3257, with additional nodes in our colocation footprint. The operating principle is that no single node failure should affect resolution latency. We share the current node count and locations under NDA — the honest answer is 'sized for resilience, not for a billboard.'
Frequently scoped alongside this work.
DDoS Mitigation
Traffic scrubbing and BGP-level filtering on AS54098 for the floods that don't politely stop. We design the runbook in advance so the 3 a.m. version isn't a first draft.
IP Transit (BGP)
Full BGP transit on AS54098 with direct peering at Hurricane Electric and transit through GTT into the rest of the Tier-1 fabric. Bring your own ASN and prefixes — we handle the policy and the on-call.
24/7 NOC
Eyes on your network around the clock, run by the engineers who write the runbooks. Pages routed to humans, not a ticket queue — for incidents that need a real person at 3 a.m.
Network Architecture and Engineering
Design, review, and hands-on implementation. The same engineers writing the design are the ones who pick up the phone when a route flaps.