Skip to content
DNS · Nameservers

Security

Nameservers and domain verification

Edge DNS uses a unique nameserver pair per account to ensure only you can add and manage your domains.

On this page8 sections

The domain ownership problem#

Traditional DNS services use shared nameservers (e.g. ns1.provider.com). This creates a security risk: anyone could potentially add your domain to their account if they know you’re using the same provider.

Edge’s unique nameserver solution#

Every Edge account is assigned a unique pair of nameservers. When you add a domain, we verify that the domain’s NS records point to your specific nameservers before activating the zone.

Your unique nameservers:

Text
ns1-{your-id}.edge.network
ns2-{your-id}.edge.network

The {your-id} portion is a unique six-character identifier assigned to your account.

How verification works#

  1. You add a domain. Enter your domain name in the Edge console. The zone is created with “pending” status.
  2. Update your registrar. Change your domain’s nameservers at your registrar to your unique Edge nameservers.
  3. We verify ownership. When you click Verify, we query public DNS for your domain’s NS records using DNS-over-HTTPS for fresh, uncached results.
  4. Zone activated. If both your nameservers are present in the response, your zone is activated instantly and begins serving DNS queries.

Technical details#

Verification process#

  • Uses Cloudflare DNS-over-HTTPS (1.1.1.1) for fresh lookups
  • Falls back to the system resolver if DoH is unavailable
  • Requires both nameservers to be present
  • Uses a case-insensitive comparison

Check your domain’s current nameservers:

Terminal
dig NS example.com +short

Expected output (your unique pair):

Text
ns1-abc123.edge.network.
ns2-abc123.edge.network.

Infrastructure: wildcard DNS#

To support the unique nameserver system at scale, Edge uses a wildcard DNS record for all nameserver subdomains:

Text
# In edge.network zone:
*.edge.network. 300 IN A 185.x.x.x
*.edge.network. 300 IN A 185.x.x.y

This means any ns1-*.edge.network or ns2-*.edge.network hostname automatically resolves to Edge’s DNS servers. No per-customer DNS management is required.

Security benefits#

  • Prevents domain hijacking: no one can add your domain to their account because they don’t have your unique nameservers.
  • Proof of control: updating nameservers requires access to your domain registrar, proving you control the domain.
  • Audit trail: the unique identifier in your nameservers provides an audit trail linking domains to accounts.
  • Instant verification: there’s no waiting for TXT record propagation or email verification. Update NS and verify.

Frequently asked questions#

Can I use the same nameservers for all my domains?#

Yes. Your unique nameserver pair is assigned to your account, not to individual domains. Use the same nameservers for all domains in your Edge account.

What if verification keeps failing?#

DNS propagation can take up to 48 hours. Wait a few hours and try again. If issues persist, make sure your registrar shows the correct nameservers with no typos.

Can I regenerate my nameservers?#

Currently, nameserver pairs are permanent. Contact support if you believe your nameservers have been compromised.

Why two nameservers?#

DNS best practice requires at least two nameservers for redundancy. Both resolve to Edge’s anycast network but provide failover if one is unreachable.

Next steps