Need email infrastructure? Try PostScale, transactional email API built in the EU. PostScale

    Primary & Secondary DNS

    Secondary DNS ThatScales Globally

    Add DNScale alongside your existing DNS provider for redundancy, DDoS resilience, and faster resolution worldwide when parent delegation includes DNScale. Sync through API, Terraform, DNSControl, or reviewed provider snapshots.

    Why add a secondary DNS provider?

    A single DNS provider is a single point of failure. When it goes down, your domains go dark, websites, APIs, email, everything.

    DDoS Resilience

    Anycast network absorbs attack traffic across multiple continents. No single target, no single point of failure.

    Global Performance

    Queries answered from the nearest point of presence. Sub-second BGP failover, not dependent on DNS TTL expiry.

    API-First Sync

    No self-serve AXFR/IXFR flow. Use Terraform, DNSControl, REST API, or provider snapshots to keep reviewed DNS state reproducible.

    How it works

    Three steps to prepare DNScale as an additional authoritative provider.

    1

    Create your zone

    Sign up and create your DNS zone on DNScale, via the dashboard or the REST API.

    2

    Sync your records

    Use Terraform, DNSControl, or the API to push reviewed records to DNScale alongside your source provider.

    3

    Add nameservers

    When your registrar and provider setup allow it, add DNScale nameservers to the parent delegation so resolvers can query both providers.

    Built for reliability

    Whether you use DNScale as your primary provider, an additional delegated provider, or a promotion target, the same infrastructure powers every query.

    Anycast Network

    Multiple points of presence across Europe, North America, Asia-Pacific, Latin America, and Africa.

    Dual-AS Architecture

    Independent EU and Global networks with automatic BGP failover between them.

    Infrastructure as Code

    Terraform provider and DNSControl support for fully declarative, version-controlled DNS.

    DNSSEC

    Automated key management with per-provider signing support for multi-provider setups.

    Query Analytics

    Per-zone and per-edge traffic visibility with response latency metrics and resolver tracking.

    20+ Record Types

    A, AAAA, CNAME, MX, TXT, SRV, CAA, TLSA, SVCB, HTTPS, and more, all managed via API.

    DNScale vs traditional secondary DNS

    API-based synchronization instead of legacy zone transfers.

    FeatureTraditional (AXFR)DNScale
    Sync methodZone transfer (AXFR/IXFR)API / Terraform / DNSControl
    SetupTSIG keys, firewall rules, SOA tuningAPI key + declarative config file
    Works with API/IaC sourcesOnly if primary supports AXFRYes, for snapshots, drift checks, and reviewed sync plans
    PropagationPull-based (SOA refresh interval)Push-based (immediate on deploy)
    AutomationCustom scripts or manualCI/CD native with drift detection
    Global anycastVaries by providerMultiple POPs, dual-AS
    Record typesLimited by transferFull support for 20+ types
    Version controlNot inherently supportedRecords defined in Git

    Works with provider APIs and DNS-as-code

    DNScale can inventory external DNS state and prepare reviewed sync or promotion plans. Cloudflare full-setup zones remain snapshot/control-plane only until delegation can include another authoritative provider.

    Cloudflare API snapshotsAWS Route 53Google Cloud DNSAzure DNSHetzner DNSDigitalOcean DNSLinode DNSNS1DynGoDaddyNamecheapOVH

    Add DNScale to your DNS infrastructure

    Get started with a free account. No credit card required. Prepare DNScale as a promotion target or additional delegated provider in minutes.