Need cloud computing? Get started now

Edge DNS

Get advanced DNS security with unmatched resiliency and performance.

Get unmatched security, performance, and availability with Akamai Edge DNS

Experience a highly scalable and flexible DNS security solution that provides:

  • Comprehensive security. Protect your DNS infrastructure from increasingly large, frequent, and sophisticated attacks — in cloud, on-prem, or hybrid 
  • Unmatched performance. Let the world’s most distributed platform alleviate origin load, provide 24/7 availability, and reduce page load time
  • Intuitive management. Self-configure and manage your DNS zones, and enforce your own dynamic policies in real time

Elevate your DNS security and performance using our powerful edge platform

Count on nonstop DNS availability

Depend on 100% uptime SLA and resilient architecture for mission-critical DNS.

Protect your on-prem and hybrid DNS assets

Protect and optimize your on-prem and hybrid DNS investments.

Achieve peace of mind with secondary DNS

Fortify DNS availability by using internet-facing secondary zones.

How Edge DNS works

Configure

Configure

Customize your primary and secondary DNS zones via APIs or tools such as Terraform through the Akamai Control Center.

Secure

Secure

Utilize optional DNSSEC features to prevent attacks caused by DNS forgery.

Deploy

Deploy

Provision, delegate, and update your zones — in the cloud or on-prem — through the Akamai Control Center to go live.

Monitor

Monitor

View and report on traffic and service availability, and monitor zones for brand spoofs and phishing domain names.

Attack superhighway C2 analysis reveals enterprise attackers
State of the Internet/Security

What can an analysis of malicious DNS traffic reveal about your organization’s risk exposure?

DNS is one of the oldest internet infrastructures, but an incredible amount of attack traffic passes through it. See details about the most prevalent threats in our latest report.

Features

  • Enable the use of a logical nameserver on multiple physical servers deployed worldwide
  • Use a bidirectional reverse proxy service that protects your on-prem and hybrid DNS assets from resource exhaustion (NXDOMAIN) attacks
  • Protect DNS from attackers exploiting vulnerabilities and risks such as source address spoofing
  • Prevent attacks caused by DNS forgery with Domain Name System Security Extensions (DNSSEC)
  • Allow developers to automate Edge DNS through APIs and existing management tools
  • Prevent IP address spoofing attacks by prioritizing workflow for trusted recursive nameservers
  • Leverage a unique architecture that segments DNS resources across nonoverlapping clouds
  • Gain actionable insights and analytics on peacetime and under-attack DNS infrastructure performance

Protect your on-prem and hybrid DNS infrastructure

Akamai Shield NS53 is a reverse proxy solution that protects on-prem and hybrid DNS infrastructure — including GSLBs, firewalls, and nameservers — from resource exhaustion attacks. Customers can self-configure, manage, and enforce their own dynamic policies in real time.

Drop NXDOMAIN DNS queries at the edge

Protect your DNS infrastructure from NXDOMAIN attacks in real time with self-configurable dynamic security policies.

Experience flexibility and ease of use

Self-configure and manage your own security policies, rate controls, APIs, and zone transfers with an easy, intuitive UI.

Accelerate performance with global anycast

Reduce latency and improve user experience with Akamai’s NAMES network, global IP anycast, and cached responses.

Frequently Asked Questions (FAQ)

Many organizations under-deploy their DNS infrastructure and often depend on just two or three DNS servers to support their global operations. This can have a serious impact on DNS performance and leave their DNS deployment — and their entire web infrastructure — unable to scale, and increasingly vulnerable to data center outages and DNS-based distributed denial-of-service (DDoS) attacks. Edge DNS is built on Akamai’s extensive edge network, which is overscaled to handle peak traffic for all of our customers, even when under attack.

It is not uncommon for organizations to have some on-prem DNS nameservers and GSLBs for administrative or compliance requirements, and not be able to migrate all their zones to a cloud-based authoritative DNS solution.  In such cases, Shield NS53, Akamai’s bidirectional reverse proxy service, offers comprehensive security from malicious attacks, and improves performance by enabling customers to self-manage policies, access control lists, and caching responses to alleviate the load on their on-prem DNS infrastructure.

IP anycast is a network addressing and routing methodology that allows IP addresses to be announced from multiple points on the internet. In the context of DNS, IP anycast describes how multiple nameservers will have the same IP address and respond to a DNS query made to that address, ensuring that the user always connects to the closest server for performance and availability.

Edge DNS does support DNSSEC. Customers that require support for DNSSEC should purchase the Secure Option of Edge DNS.

Edge DNS provides an availability SLA with guaranteed 100% uptime. Additionally, Edge DNS does not charge you any extra fees for DDoS-related traffic — which can be substantial, given the size of modern attacks.

Akamai understands that having a single solution for provisioning and configuration of both zone and traffic management can be important for our customers, which is why we are combining the capabilities of these two solutions into one. Now, with Edge DNS, you also have:

  • A way to simplify workflows to configure policies, such as geographic-driven answers
  • Convenient access to more extensibility and flexibility for DNS workflow
  • A low-cost way to handle unique addressing requirements such as compliance

DNS Security Use Cases

Learn how Akamai’s DNS security assists with these specific needs.

Comprehensive DDoS protection

Comprehensive DDoS protection

Edge DNS provides you with the scale and capabilities for normal operation, even when high-volume incidents are occurring, delivering nonstop availability of web applications and APIs. It also provides zone apex mapping and integrated traffic management with a 100% uptime SLA.

Unify your DNS security posture

Unify your DNS security posture 

Leverage the scale and power of Edge DNS as a cloud-based authoritative DNS solution or combine it with Shield NS53 to protect and intuitively manage your on-prem and hybrid DNS infrastructure to unify your DNS security. Additionally, utilize Edge DNS and Shield NS53 with Prolexic — Akamai’s purpose-built DDoS protection platform — to protect your digital infrastructure across all layers, ports, and protocols. 

Secondary DNS

Secondary DNS

Get management of DNS secondary zones on internet-facing DNS infrastructure and added protection for primary DNS resources, with a highly available secondary resource.

Actionable insights from DNS analytics

Actionable insights from DNS analytics

Get incisive insights from peacetime as well as under-attack traffic and performance of your DNS infrastructure to proactively plan and secure your online web presence. 

DNS code and traffic management

DNS code and traffic management

Simplify and automate DNS workflows by integrating Edge DNS with standard DevOps toolkits and resources through APIs. Edge DNS distributes DNS queries to optimize response times and maintain availability in response to data center/server health, providing operational simplicity, optimal app/API performance, and high availability.

Customer story

Global high tech giant ASUS relies on Akamai to deliver & secure online experiences

Resources

Free trial: Try Edge DNS for 30 days

Discover the benefits of Edge DNS or Shield NS53 for yourself:

  • Nonstop DNS availability, guaranteed
  • Protect your on-prem and hybrid DNS assets
  • Achieve peace of mind with secondary DNS

Set up your 30-day free trial:

  1. Submit form
  2. Confirm your email
  3. Pass Akamai’s validation and vetting process
  4. Receive login instructions
  5. Log in and set up your instance of Edge DNS or Shield NS53

Terms and restrictions apply.