Not a reseller console with a customer panel bolted on. Every screen assumes you are the one who has to fix DNS when something breaks.
A, AAAA, CNAME, MX, TXT, NS and SRV on every plan, including free. Growth adds ALIAS, which works at the zone apex where CNAME cannot. Business and above add CAA, PTR, TLSA, SVCB, HTTPS, SSHFP, DNAME, NAPTR and the rest — 21 in total.
One action signs the zone. Keys are generated and rolled for you; you copy the DS record to your registrar once and forget about it.
Every change stores a complete copy of the zone, not a diff. Compare any two points in time, see exactly what moved, and roll back to the good one.
Deleting a domain is the one mistake you cannot undo anywhere else. Here it waits for you, complete with its records, for as long as your plan allows.
Google Workspace, Microsoft 365, Zoho, FastMail, Shopify, Squarespace and more. Every preset previews each record as add or replace, with the current value beneath it, before anything is written.
How many lookups each domain answered each day, split into successes, NXDOMAIN and SERVFAIL. A spike in NXDOMAIN usually means a record somebody expects is missing; SERVFAIL means something is genuinely broken. Three years of history.
Load a BIND zone file to move in, and download one whenever you want out. Available on every plan, including free — your records are yours.
Changes publish to every nameserver in the background, and the panel shows you which servers have it and which have not. No wondering whether it went out.
Refresh, retry, expire, negative caching and per-record TTLs are all editable, with sane defaults if you would rather not think about them.
Authoritative nameservers in multiple datacentres globally.
If your DNS goes down, everything goes with it. Your site, your email, your API — all unreachable, even though those servers are fine.
Our nameservers are DDoS-protected on every plan, including the free one. It is not an add-on, and there is no cheaper tier answered from somewhere less defended.
Every plan carries a 100% monthly availability commitment for authoritative DNS resolution — the free plan included. SLA service credits are available for paid plans. Please refer to Service Level Agreement.
Bring colleagues into your account without handing round one password. Each person signs in as themselves, sees only the domains you assign them, and can do only what you allow.
A member sees the zones you assign and nothing else. Someone who looks after one brand never sees the rest of the portfolio — not in their zone list, not in statistics, not through an API key they create.
Twenty of them, grouped by what they touch. Delete records is separate from editing because it is the one that loses data, and viewing is separate again — a member without it sees the zone name and nothing in it.
Invoices, payment methods, the plan itself and closing the account are owner-only and cannot be granted. A member can run your DNS without ever seeing what you pay for it.
Give the person who runs the shop the shop’s domain, and the person who runs the mail server the domains whose MX they maintain. Nobody needs the account password, nobody can touch a domain that is not theirs, and when somebody leaves you remove one member instead of changing one password and telling everyone the new one.
Your plan’s zones are a pool, and a member can be allowed to create from it. Give each client a login capped at the number of zones you have sold them — the cap is set per group, so a client on five zones cannot quietly become a client on fifty. A zone they create is assigned to them automatically, so they administer their own domains and see nobody else’s.
Business includes 100 members. Enterprise is unlimited.
The free plan hosts a zone with 100 records and no card. If it suits you, move the rest across.