3 min readbeginner
Is DNS centralised or decentralised?
DNS was designed as a distributed system, yet in practice a handful of providers answer most of the internet's queries. That gap between design and reality matters.
CoversDNS
The short answer: both#
By design, DNS is decentralised: it’s a federated hierarchy in which root servers, top-level-domain registries, and millions of independent authoritative nameservers each answer for their own slice of the namespace, with no single machine holding the whole map. In practice, however, DNS hosting has become heavily concentrated. A small number of large providers serve the authoritative records for an enormous share of popular domains.
So the honest answer is that the protocol is decentralised but the operational reality is increasingly centralised. It’s the operational reality that determines what happens when something breaks.
Why concentration is a problem#
DNS is the step before everything else: if name resolution fails, your site is offline for practical purposes even though your servers are healthy. When many domains share one DNS provider, that provider becomes a single point of failure for all of them at once. The pattern has played out repeatedly, most famously in the 2016 DDoS attack on the DNS provider Dyn, which took major sites including Twitter, Spotify, and Reddit offline for hours, and in subsequent outages at other large providers that each removed a visible chunk of the web.
Concentration also raises subtler risks: a single provider is a bigger, more attractive target for attackers; a configuration error propagates to every zone the provider hosts; and censorship or policy decisions at one company can affect a large fraction of the namespace.
What decentralised DNS means#
Decentralised DNS pushes the infrastructure that answers queries back out toward the edges of the network. Instead of resolving from a handful of large facilities, queries are answered by a distributed network of nodes, with Anycast routing sending each query to the nearest one. The failure of any node, or even a whole region, leaves the rest of the network answering as normal, and a volumetric attack has no single chokepoint to saturate.
Practical resilience follows from the same principle applied at the zone level: serving DNS from a distributed network, signing zones with DNSSEC so answers can’t be forged, and using health checks with automatic failover so traffic moves away from failed origins without human intervention.
How Edge DNS works#
Edge DNS runs on the same distributed network as the rest of the platform, with unlimited DDoS mitigation included.
- Global Anycast: queries are answered from the nearest of 50+ locations worldwide, with sub-10ms average resolution.
- Instant propagation: record changes propagate globally in under 5 seconds, so there’s no waiting for updates to take effect.
- Automatic failover: health checks are included, and traffic is routed away from unhealthy origins automatically.
- DNSSEC: one-click zone signing protects domains from spoofing and cache poisoning.
DNS resilience in practice#
Edge DNS is free to use for up to 50 zones, with unlimited records and a million queries a month per zone included, and there are no per-domain fees. Health checks and geo-routing are included rather than sold as extras, and the DNS Examiner will analyse a zone’s security, email deliverability, and nameserver configuration in one click. You can see how it stacks up against Cloudflare, Route 53, and DNSimple on the DNS comparison page.
Whichever provider you use, the lesson of the last decade of DNS outages is the same: treat DNS as critical infrastructure, prefer providers with distributed Anycast networks and DDoS protection, enable DNSSEC, and configure failover before you need it. Our DNS failover guide walks through the setup.
Put your zones on a distributed network#
Fast Anycast DNS with DNSSEC, health checks and failover. Free for up to 50 zones.
Next steps
Keep learning
Tutorials2 min read
Configuring DNS failover
How Edge DNS handles routing and failover: what works today, what doesn't yet, and practical workarounds for high availability.
Background4 min read
Edge network security
The network edge is where your infrastructure first meets the open internet, which makes it the best place to stop attacks. Here's what securing the edge involves.
Edge explained4 min read
What is an edge network?
Edge networking moves computing power out of distant data centres and puts it close to the people using it. Here's how edge networks work, and why the internet is being rebuilt around them.