Edge DNS
Host a zone for each of your domains and answer DNS queries for its records from three authoritative nameservers on Azion's distributed infrastructure.
Every domain on the internet relies on an authoritative DNS service: the nameservers that hold the domain’s records and give the final answer about them. A browser or a mail server does not ask those nameservers itself. Its resolver, the DNS server that performs lookups for it, follows the domain’s delegation from its registry and asks one of them. With a hosted service, you write the records, and the provider runs the nameservers that answer.
Edge DNS hosts a zone for each of your domains and answers queries for the zone’s records from Azion’s distributed infrastructure. Three nameservers, ns1.aziondns.net, ns2.aziondns.com, and ns3.aziondns.org, serve every zone, and a domain reaches them once its registrar delegates it to all three. Edge DNS is authoritative only, not a resolver, so your users keep their own resolvers while you manage records instead of nameserver software. Use Edge DNS to point domains and subdomains at your servers, receive mail, verify ownership, restrict certificate issuers, or share traffic by weight.
Zones and records
A zone holds one domain, such as example.com, and every record that Edge DNS answers for it. A record maps one name inside the zone to a type and one or more values. This request body, sent as a POST to /v4/workspace/dns/zones/<zone-id>/records, adds a record that answers 192.0.2.1 for www.example.com:
nameis written relative to the zone.wwwanswers forwww.example.com,@names the apexexample.com, and a*label makes a wildcard.typeis one of the 11 record types Edge DNS hosts.Amaps the name to an IPv4 address.rdatacarries the answers, which Azion Console calls Value. An A record holds up to 10 addresses.ttlsets how many seconds a resolver may cache the answer. A record that sends no TTL gets3600.
The Console’s Create Record drawer and azion create dns-record take the same four fields. A record carries what one line of a standard zone file carries, so if you have edited a zone file, you know the record model. Every field and its default is on Zones and records, and the section’s vocabulary is on the Glossary. To create a zone in any interface, refer to Create, edit, or delete a zone.
Resolution path
Creating a zone does not make the internet ask Azion about the domain. Queries reach a zone only through the delegation that the domain’s registrar publishes.
- At the registrar, you delegate the domain to all three Edge DNS nameservers. Until the delegation is published, public resolvers find no path to Azion.
- A resolver that looks up
www.example.comfollows the delegation and sends the query to one of the three nameservers. - The nameserver selects the zone whose domain matches the query, then the record whose name and type match.
- The nameserver returns the record’s values as an authoritative answer, and the resolver caches that answer for the record’s TTL.
You can build and check a zone before step 1. A query sent straight to ns1.aziondns.net returns what the zone answers, while public resolvers still follow the domain’s current delegation. To send that query, refer to Query a zone with dig. For how caching delays a change, how weighted and ANAME records answer, and how DNSSEC signs a zone, refer to How Edge DNS works.
Scope and limits
- Record types: a zone holds 11 types: A, AAAA, ANAME, CAA, CNAME, DS, MX, NS, PTR, SRV, and TXT. The API refuses any other type, such as
SOA. Each type, its value format, and its RFC are on Record types. - Policies: a Simple record answers with all of its values. Weighted records share one name and type, and each is answered in proportion to its weight, from 0 to 255. Refer to Record policies.
- Apex: a CNAME is refused at
@. An ANAME record points the apex at a hostname underazioncdn.net,azionedge.net, orazionedge.com, with a TTL of20. Refer to Point an apex domain with ANAME. - DNSSEC: you turn DNSSEC on for a zone yourself, in the Console, the CLI, or the API. Azion signs the zone and generates the DS values you add at your registrar. Refer to DNSSEC.
- Nameservers: the same three nameservers serve every zone, and they are read-only. Delegate the domain to all three. Refer to Nameservers and SOA.
- Propagation: a saved record needs no deployment step, and a new name that nobody queried before it existed answers within seconds. A change to an existing record can take a few minutes to reach every nameserver. A name queried before it existed is answered
NXDOMAINfor up to one hour, the SOA minimum. Refer to Caching and propagation and Best practices for Edge DNS. - Interfaces: you manage zones and records in Azion Console, with the Azion CLI, through the Azion API, and with the Azion Terraform provider.
- Observability: the Total Queries chart of the Real-Time Metrics Edge DNS dashboard counts the queries your zones receive. Real-Time Events keeps one entry per query, and the GraphQL API returns the data aggregated or raw.
- Limits: a zone name takes 1 to 50 characters, and a TXT value up to 1,000. An A, AAAA, or MX record holds up to 10 values. Every bound is on Edge DNS limits.
- Billing: Edge DNS is billed on two metrics: Zones, the daily average of active zones in a monthly cycle, and Queries, the DNS queries it processes. The amounts each plan includes are on Included usage per plan, and the rates on Pricing.
- Security: Azion’s DDoS Protection also protects the DNS service, and the attacks it mitigates include DNS floods, even of well-formed queries.
- Terms: the domain stays registered at your registrar, where you change its nameservers and renew it, and you keep its zones and records correct. Azion may remove zones that are not in use. Refer to the Terms of Service.
When a zone does not answer as expected, refer to Troubleshoot Edge DNS.