Primary & Secondary DNS
Secondary DNS ThatScales Globally
Add DNScale alongside your existing DNS provider for redundancy, DDoS resilience, and faster resolution worldwide when parent delegation includes DNScale. Sync through API, Terraform, DNSControl, or reviewed provider snapshots.
Why add a secondary DNS provider?
A single DNS provider is a single point of failure. When it goes down, your domains go dark, websites, APIs, email, everything.
DDoS Resilience
Anycast network absorbs attack traffic across multiple continents. No single target, no single point of failure.
Global Performance
Queries answered from the nearest point of presence. Sub-second BGP failover, not dependent on DNS TTL expiry.
API-First Sync
No self-serve AXFR/IXFR flow. Use Terraform, DNSControl, REST API, or provider snapshots to keep reviewed DNS state reproducible.
How it works
Three steps to prepare DNScale as an additional authoritative provider.
Create your zone
Sign up and create your DNS zone on DNScale, via the dashboard or the REST API.
Sync your records
Use Terraform, DNSControl, or the API to push reviewed records to DNScale alongside your source provider.
Add nameservers
When your registrar and provider setup allow it, add DNScale nameservers to the parent delegation so resolvers can query both providers.
Built for reliability
Whether you use DNScale as your primary provider, an additional delegated provider, or a promotion target, the same infrastructure powers every query.
Anycast Network
Multiple points of presence across Europe, North America, Asia-Pacific, Latin America, and Africa.
Dual-AS Architecture
Independent EU and Global networks with automatic BGP failover between them.
Infrastructure as Code
Terraform provider and DNSControl support for fully declarative, version-controlled DNS.
DNSSEC
Automated key management with per-provider signing support for multi-provider setups.
Query Analytics
Per-zone and per-edge traffic visibility with response latency metrics and resolver tracking.
20+ Record Types
A, AAAA, CNAME, MX, TXT, SRV, CAA, TLSA, SVCB, HTTPS, and more, all managed via API.
DNScale vs traditional secondary DNS
API-based synchronization instead of legacy zone transfers.
| Feature | Traditional (AXFR) | DNScale |
|---|---|---|
| Sync method | Zone transfer (AXFR/IXFR) | API / Terraform / DNSControl |
| Setup | TSIG keys, firewall rules, SOA tuning | API key + declarative config file |
| Works with API/IaC sources | Only if primary supports AXFR | Yes, for snapshots, drift checks, and reviewed sync plans |
| Propagation | Pull-based (SOA refresh interval) | Push-based (immediate on deploy) |
| Automation | Custom scripts or manual | CI/CD native with drift detection |
| Global anycast | Varies by provider | Multiple POPs, dual-AS |
| Record types | Limited by transfer | Full support for 20+ types |
| Version control | Not inherently supported | Records defined in Git |
Works with provider APIs and DNS-as-code
DNScale can inventory external DNS state and prepare reviewed sync or promotion plans. Cloudflare full-setup zones remain snapshot/control-plane only until delegation can include another authoritative provider.
Add DNScale to your DNS infrastructure
Get started with a free account. No credit card required. Prepare DNScale as a promotion target or additional delegated provider in minutes.