Managed DNS is a service in which a provider hosts the authoritative Domain Name System records for your domains and answers lookups for them from its own servers. When someone types your web address or sends you email, their resolver asks your authoritative DNS where to go; with managed DNS, that answer comes from the provider’s network instead of a server you run. The term covers everything from free DNS hosting bundled with a registrar to paid services with global server networks, traffic steering and DDoS protection.
At a glance
- Managed DNS hosts the authoritative records for your own domains; it is not the resolver your staff use to browse, which is where DNS filtering works.
- Many providers answer from many locations using anycast, which can cut lookup times and spread load.
- Paid tiers often add traffic steering, health checks, DNSSEC signing, APIs and query analytics.
- If DNS for a domain fails, the services that depend on that domain can become unreachable, which is why some organizations use two providers.
What problem it solves
DNS is the first step in reaching almost every internet service a business runs: its website, email, customer portals, VPN and APIs. If the authoritative servers for a domain stop answering, those services can become unreachable even though they are still running. Running your own authoritative DNS well takes servers in several locations, protection against attacks and someone who keeps it patched.
Managed DNS hands that work to a provider whose network is built for it. It also tends to fix a common mess: records spread across a registrar, a web host, an old in-house server and a cloud account, with nobody sure which copy is live. Consolidating onto one managed provider, or a deliberate pair, gives the business a single place to change records and a clear view of what exists.
How it works
Delegation. At your domain registrar, you set the domain’s name servers to the ones your managed DNS provider gives you. From then on, resolvers around the internet send questions about your domain to the provider.
Zones and records. You manage records (such as A, AAAA, CNAME, MX and TXT) through the provider’s portal or API. Changes typically reach the provider’s servers within seconds to minutes, then spread to resolvers as cached answers expire.
Distributed answering. Many providers run servers in many locations and announce the same addresses from all of them, so each lookup usually reaches a nearby, working server. Coverage, capacity and resilience vary by provider and tier.
Advanced features. Depending on the service, these may include geographic or latency-based routing, failover driven by health checks (a basic form of global server load balancing), DNSSEC signing, secondary DNS, detailed logs and role-based access for teams.
Resilience. Providers commonly offer an availability SLA. Some organizations add a second provider so that an outage at one does not take their domains offline, keeping records in sync through zone transfers or automation.
Managed DNS is often bought with, or included in, a CDN or edge security service; see our Cloud and Content Delivery Network solution page.
When it matters for buyers
- After a DNS outage. A provider outage or an expired domain can take down a website and email at once, which often prompts a review.
- Website or email migrations. Moving hosting or email is a good time to consolidate records and confirm who controls the account.
- Mergers and inherited domains. Acquired companies bring domains hosted in unknown places, sometimes in a former employee’s account.
- Global audiences. Customers spread across regions benefit from a provider that answers from many locations.
- DDoS exposure. Attacks on DNS can make services unreachable, so ask how the provider absorbs DDoS traffic and what the plan covers.
Questions to ask vendors
- Where are your authoritative servers, and do you use anycast across them?
- What availability SLA do you offer, and what credits apply if you miss it?
- How do you protect DNS against DDoS attacks, and are there query or overage charges during an attack?
- Do you support DNSSEC, secondary DNS and zone transfers to or from another provider?
- What traffic steering and health-check features are included, and which cost extra?
- Is there an API, change history and role-based access for our team?
- How do we export our zones if we leave?
How it differs from a domain registrar
A domain registrar is the company through which you register and renew a domain name and record which name servers it uses. Managed DNS is the service that runs those name servers and answers lookups. Many registrars include basic DNS hosting, so buyers often use one company for both without realizing they are separate jobs. They can be split: the domain stays at the registrar and DNS moves to a specialist provider by changing the name server records. Losing control of either account can take a domain offline, so both need current contacts and protected logins.
