---
title: "Nameservers and domain verification"
description: "How Edge DNS assigns each account a unique nameserver pair to verify domain ownership, prevent hijacking, and activate zones instantly after NS checks."
url: "https://edge.network/docs/dns/nameservers"
section: "DNS"
---

# Nameservers and domain verification

Edge DNS uses a unique nameserver pair per account to ensure only you can add and manage your domains.

## The domain ownership problem

Traditional DNS services use shared nameservers (e.g. `ns1.provider.com`). This creates a security risk: anyone could potentially add your domain to their account if they know you're using the same provider.

> [!CAUTION]
> **Without unique nameservers**, an attacker could add your domain to their account and intercept your traffic, read your emails or issue fraudulent SSL certificates.

## Edge's unique nameserver solution

Every Edge account is assigned a unique pair of nameservers. When you add a domain, we verify that the domain's NS records point to *your specific nameservers* before activating the zone.

Your unique nameservers:

```text
ns1-{your-id}.edge.network
ns2-{your-id}.edge.network
```

The `{your-id}` portion is a unique six-character identifier assigned to your account.

> [!TIP]
> **Cryptographic binding.** Your unique nameserver pair creates a cryptographic binding between your account and your domains. No one else can use your nameservers, and no one else can add domains using your nameservers.

## How verification works

1. **You add a domain.** Enter your domain name in the Edge console. The zone is created with "pending" status.
2. **Update your registrar.** Change your domain's nameservers at your registrar to your unique Edge nameservers.
3. **We verify ownership.** When you click **Verify**, we query public DNS for your domain's NS records using DNS-over-HTTPS for fresh, uncached results.
4. **Zone activated.** If both your nameservers are present in the response, your zone is activated instantly and begins serving DNS queries.

## Technical details

### Verification process

- Uses Cloudflare DNS-over-HTTPS (1.1.1.1) for fresh lookups
- Falls back to the system resolver if DoH is unavailable
- Requires **both** nameservers to be present
- Uses a case-insensitive comparison

Check your domain's current nameservers:

```bash
dig NS example.com +short
```

Expected output (your unique pair):

```text
ns1-abc123.edge.network.
ns2-abc123.edge.network.
```

## Infrastructure: wildcard DNS

To support the unique nameserver system at scale, Edge uses a wildcard DNS record for all nameserver subdomains:

```text
# In edge.network zone:
*.edge.network. 300 IN A 185.x.x.x
*.edge.network. 300 IN A 185.x.x.y
```

This means any `ns1-*.edge.network` or `ns2-*.edge.network` hostname automatically resolves to Edge's DNS servers. No per-customer DNS management is required.

## Security benefits

- **Prevents domain hijacking:** no one can add your domain to their account because they don't have your unique nameservers.
- **Proof of control:** updating nameservers requires access to your domain registrar, proving you control the domain.
- **Audit trail:** the unique identifier in your nameservers provides an audit trail linking domains to accounts.
- **Instant verification:** there's no waiting for TXT record propagation or email verification. Update NS and verify.

## Frequently asked questions

### Can I use the same nameservers for all my domains?

Yes. Your unique nameserver pair is assigned to your account, not to individual domains. Use the same nameservers for all domains in your Edge account.

### What if verification keeps failing?

DNS propagation can take up to 48 hours. Wait a few hours and try again. If issues persist, make sure your registrar shows the correct nameservers with no typos.

### Can I regenerate my nameservers?

Currently, nameserver pairs are permanent. Contact support if you believe your nameservers have been compromised.

### Why two nameservers?

DNS best practice requires at least two nameservers for redundancy. Both resolve to Edge's anycast network but provide failover if one is unreachable.

## Next steps

- [Getting started](/docs/dns/getting-started) — Add your first domain
- [Zone management](/docs/dns/zones) — Create and configure zones
