Authoritative DNS with DNSSEC
Primary–secondary pair with AXFR, inline record editing and one-click zone signing.
DNS, reverse proxy, tunnels and TLS — one dashboard driving real infrastructure on your own metal. No third party between your visitors and your origin.
$ dig +short app.example.com 198.51.100.10 198.51.100.11 # the edge pool answers — your origin never appears
Primary–secondary pair with AXFR, inline record editing and one-click zone signing.
Public DNS answers with a dedicated edge IP pool; the origin never leaves the record.
WireGuard-based tunnels bring private services to the edge with health and logs in the panel.
ACME DNS-01 per hostname at the edge, with live traffic split by TLS version.