Future at the Edge
Cloud DNS 101
Modern DNS Architecture and�Edge Authoritative DNS
An architectural deep dive into cloud DNS, Anycast networks,
and programmable traffic management.
All Rights Reserved © VergeCloud
Cloud DNS 101
DNS Refresher and introduction to Athoritative DNS
1
All Rights Reserved © VergeCloud
Cloud DNS 101
Every internet request starts with DNS
Cloud DNS 101
All Rights Reserved © VergeCloud
How a domain name becomes an IP address
Typically operated by an ISP or public service. Queries the hierarchy to find the IP address.
The final source of truth. Holds the official records for the domain.
If the authoritative server is slow or unavailable, the resolver cannot obtain the information.
Cloud DNS 101
All Rights Reserved © VergeCloud
The DNS Weak Link - Limitations of Registrar DNS
2
All Rights Reserved © VergeCloud
Cloud DNS 101
Registrar DNS was built for domain management
Cloud DNS 101
All Rights Reserved © VergeCloud
Centralisation creates operational fragility
Cloud DNS 101
All Rights Reserved © VergeCloud
Why Edge Cloud DNS is Faster and More Reliable
3
All Rights Reserved © VergeCloud
Cloud DNS 101
Distributing authoritative DNS to the edge
Cloud DNS 101
All Rights Reserved © VergeCloud
Anycast architecture routes to the closest topological node
Cloud DNS 101
All Rights Reserved © VergeCloud
Edge resolution eliminates single points of failure
Cloud DNS 101
All Rights Reserved © VergeCloud
Anycast delivers answers from the closest location
Lower lookup latency and consistent millisecond performance.
All Rights Reserved © VergeCloud
Cloud DNS 101
Intelligent Traffic Steering using DNS
4
All Rights Reserved © VergeCloud
Cloud DNS 101
DNS as an Active Traffic Steering Layer
Modern platforms provide advanced traffic management at the resolution layer.
Allows engineering teams to control exactly how user requests route to backend infrastructure.
DNS becomes an active enabler of reliability, rather than a passive directory.
Cloud DNS 101
All Rights Reserved © VergeCloud
Routing strategies for�modern deployment patterns
Round-robin routing
Distributing traffic evenly across multiple active endpoints.
Geolocation routing
Directing users to infrastructure located in their specific geographic region.
Weighted routing
Gradually shifting traffic between environments for canary deployments.
Cloud DNS 101
All Rights Reserved © VergeCloud
Protection Against DNS Volumetric and Spoofing Attacks
5
All Rights Reserved © VergeCloud
Cloud DNS 101
DNS is a primary target for volumetric attacks
Cloud DNS 101
All Rights Reserved © VergeCloud
Edge networks absorb and distribute attack traffic
Cloud DNS 101
All Rights Reserved © VergeCloud
Preventing DNS Spoofing with DNSSEC
Cloud DNS 101
All Rights Reserved © VergeCloud
Preventing DNS Spoofing with DNSSEC
Cryptographic Signing of DNS Records
DNSSEC adds digital signatures to every DNS record using public-key cryptography
Chain of Trust Validation
DNSSEC establishes a hierarchical chain of trust from the root zone down to individual domain records
Authenticated Denial of Existence
NSEC/NSEC3 records provide cryptographic proof that a queried domain does not exist, preventing attackers from exploiting negative responses to redirect users to malicious destinations through cache poisoning
Cloud DNS 101
All Rights Reserved © VergeCloud
SUMMARY & KEY TAKEAWAYS
6
All Rights Reserved © VergeCloud
Cloud DNS 101
Cloud Edge DNS - Key Advantages
Performance
Edge Anycast architecture delivers millisecond DNS resolution by answering queries from the nearest
PoP globally.
Resilience
Distributed infrastructure eliminates single points of failure; regional outages do not impact global DNS availability.
Intelligent Control
DNS becomes an active traffic steering layer enabling Geolocation routing, weighted rollouts, and round robin
Security
Edge networks absorb volumetric
DDoS attacks across dozens of nodes; DNSSEC prevents spoofing and cache poisoning.
Cloud DNS 101
All Rights Reserved © VergeCloud
VergeCloud Secure Edge Edge PoP Components
Cloud DNS 101
All Rights Reserved © VergeCloud
Q&A
All Rights Reserved © VergeCloud
Cloud DNS 101