One operational context
Manage DNS alongside application, email and security services instead of switching between disconnected providers.
Run your authoritative DNS on the Waffinnity DNS fleet and manage records, DNSSEC and zone lifecycle from one workspace. Waffinnity continuously checks delegation, authoritative nodes, public SOA state and the DNSSEC parent chain.
DNS controls where customers, applications and mail are reached. Waffinnity combines authoritative hosting with operational verification, so configuration and public reality are continuously compared.
Manage DNS alongside application, email and security services instead of switching between disconnected providers.
Waffinnity checks whether delegation, authoritative nodes and public DNS actually reflect the intended configuration.
DS publication and the parent chain are verified before Waffinnity considers DNSSEC fully active.
Imports, replacements, DNSSEC disablement and zone deletion use previews, validation and explicit confirmation where mistakes have impact.
The workspace is designed for customers, not DNS server administrators: common actions stay simple, while advanced controls remain available when needed.
Create, edit and delete DNS records directly without having to remove and recreate existing entries.
A · AAAA · CNAME · MX · TXT · SRV · CAA · NS · PTR · SSHFP · DS · NAPTR · URI · SVCB · HTTPSEnable signing, view DS data and verify the published DS record against public resolvers and the parent chain.
Safe disable protectionImport BIND zone files in merge or replace mode with a preview of additions, changes, conflicts and removals.
BIND zone formatA 0–100 health score summarizes delegation, authoritative fleet state, public SOA/serial consistency and DNSSEC.
Live operational checksDetect when the registrar still points to other nameservers or when public delegation does not match the Waffinnity fleet.
Public verificationWaffinnity periodically reconciles managed zones and health state, even when nobody has the DNS workspace open.
Background operationsZone deletion requires explicit domain confirmation and DNSSEC cannot be disabled while a public DS record is still present.
Fail-safe lifecycleImportant DNS and DNSSEC actions are captured in the platform audit trail for visibility and accountability.
Audit trailAdd the domain to Waffinnity and prepare the authoritative zone before changing delegation.
Import an existing BIND zone or add and edit records directly in the workspace.
Review the zone and let Waffinnity synchronize it across the authoritative fleet.
Point the domain to the Waffinnity nameservers and follow public health until delegation is converged.
Waffinnity treats DNSSEC as an operational lifecycle instead of a simple switch. Signing state, DS data and parent publication are kept separate so unsafe transitions can be blocked.
Manage zones, DNSSEC and public DNS health without losing sight of the applications and mail services that depend on them.