HYX

Product plane / Hyx DNS

Hyx DNS

operational

Authoritative DNS built for fast answers and safe change.

Hyx DNS serves your zones on a distributed, dual-stack Anycast fabric. Scan or import the current zone, move nameservers only after review, sign with DNSSEC, and choose exactly which web records use the Hyx proxy.

01 / proof
IPv4 + IPv6
Anycast ingress
Authoritative DNS on a dual-stack serving fabric.
02 / proof
9
managed record types
A through CAA, including mail and service records.
03 / proof
DNSSEC
signed zone support
Registrar-ready DS and DNSKEY details.
04 / proof
per record
routing control
DNS only or Hyx-proxied where supported.

Core capabilities

Move a zone without turning migration into an outage.

Hyx reads the live authoritative zone or a standard BIND export, lets you review what will move, and verifies delegation after the nameserver change. Day-to-day record, proxy, export, and signing controls stay in the same dashboard.

DNS-01 / example.com / authoritative zone

delegated / signed

Managed record types

09

Zone integrity

DNSSEC / DS ready

NameTypeValueRoute
@A203.0.113.10Proxied
wwwCNAMEexample.com.Proxied
@MXmail.example.com.DNS only
_dmarcTXTv=DMARC1; p=rejectDNS only

Scan existing DNS or import a BIND zone, review records, then delegate without rebuilding the zone by hand.

Ingress

Anycast v4 + v6

Migration

Scan / BIND

Signing

DNSSEC

01

Anycast authoritative DNS

Serve authoritative answers from the distributed Hyx DNS fabric instead of a single location.

02

Guided DNS migration

Scan a domain's current authoritative DNS, review every discovered record, and move nameservers last.

03

BIND zone import and export

Bring an exported zone file into Hyx or download a Hyx zone for backup and portability.

04

Complete record management

Create and edit the record types modern sites, mail, verification, and service discovery depend on.

05

DNS-only or Hyx-proxied records

Keep a record on authoritative DNS alone or route eligible web traffic through Hyx delivery and protection.

06

DNSSEC signing

Sign a zone in Hyx and publish the supplied DS details at the registrar to protect the chain of trust.

How it works

Short query paths. Ordered control-plane changes.

Resolvers reach the Hyx DNS fabric through Anycast while zone changes travel through a versioned stream to connected DNS edges. DNSSEC protects the chain of trust, and API-side safeguards keep critical glue records routable.

DNS-02 / query and change paths

authoritative / distributed

Query / resolver to signed answer

01

Recursive resolver

02

Anycast ingress

03

Nearest Hyx DNS edge

04

Authoritative answer

Change / control plane to serving fabric

01

Dashboard

02

Versioned journal

03

Connected DNS edges

Query target

Nearest edge

Change order

Versioned

Delegation

Verified

  1. 01

    Discover

    Scan the domain's current authoritative DNS or load a BIND-format zone file.

  2. 02

    Review

    Check every record, choose what to import, and correct anything before delegation changes.

  3. 03

    Delegate

    Move nameservers at the registrar last; Hyx checks the live delegation automatically.

  4. 04

    Operate

    Manage records, proxy eligibility, zone exports, and DNSSEC from one control plane.

Operational detail

Capabilities included with Hyx.

A concise list of what this part of Hyx provides. Roadmap items are labelled explicitly.

Open the full matrix

Included

09
  • Anycast authoritative DNS

  • Guided DNS migration

  • BIND zone import and export

  • Complete record management

  • DNS-only or Hyx-proxied records

  • DNSSEC signing

  • Automatic delegation checks

  • Versioned network updates

  • Nameserver glue safeguards

Next system / Performance

Carry selected DNS records into the Hyx delivery path.

See how the Hyx edge accelerates cacheable content, optimizes delivery, and keeps work away from your server.

Continue to Performance