Skip to content
Waffinnity
Get started
WAFFINNITY MANAGED DNS

DNS that is not just hosted, but continuously verified.

Run your authoritative DNS on the Waffinnity DNS fleet and manage records, DNSSEC and zone lifecycle from one workspace. Waffinnity continuously checks delegation, authoritative nodes, public SOA state and the DNSSEC parent chain.

Authoritative DNSDNSSECContinuous health monitoring
DNS OPERATIONSexample.eu
Healthy
ZONE HEALTH100/100
DNSSEC ACTIVE
DelegationNameservers match the managed fleet
OK
Authoritative fleetAll DNS nodes answer correctly
OK
SOA & serialPublic state matches the control plane
OK
DNSSEC parent chainDS record verified publicly
OK
Automatically checked by Waffinnity DNS Operations
DNS is part of your security perimeterAUTHORITATIVE DNSDNSSECZONE HEALTHEU CONTROL PLANE
WHY MANAGE DNS WITH WAFFINNITY

Because a DNS change should never become an invisible outage.

DNS controls where customers, applications and mail are reached. Waffinnity combines authoritative hosting with operational verification, so configuration and public reality are continuously compared.

01

One operational context

Manage DNS alongside application, email and security services instead of switching between disconnected providers.

02

Changes are verified

Waffinnity checks whether delegation, authoritative nodes and public DNS actually reflect the intended configuration.

03

DNSSEC without guesswork

DS publication and the parent chain are verified before Waffinnity considers DNSSEC fully active.

04

Safer lifecycle operations

Imports, replacements, DNSSEC disablement and zone deletion use previews, validation and explicit confirmation where mistakes have impact.

MANAGED DNS CAPABILITIES

Everything needed for day-to-day DNS operations.

The workspace is designed for customers, not DNS server administrators: common actions stay simple, while advanced controls remain available when needed.

RR

Record management

Create, edit and delete DNS records directly without having to remove and recreate existing entries.

A · AAAA · CNAME · MX · TXT · SRV · CAA · NS · PTR · SSHFP · DS · NAPTR · URI · SVCB · HTTPS
SEC

DNSSEC

Enable signing, view DS data and verify the published DS record against public resolvers and the parent chain.

Safe disable protection
IMP

Import & export

Import BIND zone files in merge or replace mode with a preview of additions, changes, conflicts and removals.

BIND zone format
HLT

Zone health

A 0–100 health score summarizes delegation, authoritative fleet state, public SOA/serial consistency and DNSSEC.

Live operational checks
DEL

Delegation monitoring

Detect when the registrar still points to other nameservers or when public delegation does not match the Waffinnity fleet.

Public verification
OPS

Automated reconciliation

Waffinnity periodically reconciles managed zones and health state, even when nobody has the DNS workspace open.

Background operations
SAFE

Protected destructive actions

Zone deletion requires explicit domain confirmation and DNSSEC cannot be disabled while a public DS record is still present.

Fail-safe lifecycle
LOG

Operational history

Important DNS and DNSSEC actions are captured in the platform audit trail for visibility and accountability.

Audit trail
FROM EXISTING DNS TO MANAGED DNS

Move without rebuilding every record by hand.

1

Create the zone

Add the domain to Waffinnity and prepare the authoritative zone before changing delegation.

2

Import or create records

Import an existing BIND zone or add and edit records directly in the workspace.

3

Validate first

Review the zone and let Waffinnity synchronize it across the authoritative fleet.

4

Change delegation

Point the domain to the Waffinnity nameservers and follow public health until delegation is converged.

DNSSEC LIFECYCLE

DNSSEC should protect the domain, not make it unreachable.

Waffinnity treats DNSSEC as an operational lifecycle instead of a simple switch. Signing state, DS data and parent publication are kept separate so unsafe transitions can be blocked.

Signing stateDS recordParent verificationPublic resolver checksSafe disable flowAudit logging
DNSSEC STATUSexample.eu
ACTIVE
SigningEnabled
DS @ parentVerified
Public resolvers3 / 3
✓ DNSSEC chain validated
WAFFINNITY MANAGED DNS

Bring DNS into the same operational platform as your security.

Manage zones, DNSSEC and public DNS health without losing sight of the applications and mail services that depend on them.

Get started →