Security & DNS
Cloudflare DNS
Authoritative DNS on a global anycast network with DNSSEC, proxying and rapid propagation, used where resolution must stay fast and available under attack.

Capabilities
What we implement
- Zone migration with a record-by-record audit
- Proxy versus DNS-only decisions per record
- DNSSEC enablement and registrar DS records
- TTL strategy for planned cutovers
Security
How it is hardened
- DNSSEC signing and registrar lock
- Account MFA and scoped API tokens
- CAA records and audit logging of zone changes
Editions & pricing
Cloudflare DNS editions and vendor pricing
Vendor list prices for the editions we deploy. Deployment, migration, hardening and support are quoted separately by Techno Trader PK — they are never bundled into these figures.
| Edition | Licensed by | Vendor list price |
|---|---|---|
| Free authoritative DNSIndicative; paid plans add WAF and performance features. | per domain / month | $0 |
Prices are checked against the vendor's published price list. Last verified 10 Sept 2026. Vendor list prices exclude tax and can change without notice.
Architecture
Authoritative DNS on anycast
Zones are migrated record by record, signed with DNSSEC and controlled with TTL discipline so cutovers are predictable.
01 · Zone migration
Record auditImport and diffNameserver delegationThe imported zone is compared against the source before delegation changes.
02 · Resolution
Anycast networkDNS-only recordsProxied recordsMail, SIP and other non-HTTP records stay DNS-only; only web traffic is proxied.
03 · Integrity
DNSSEC signingDS record at registrarCAA recordsSigning is completed at the registrar, not left half-enabled.
04 · Control
Account MFAScoped API tokensChange audit logZone changes are attributable and API access is limited to what automation needs.
FAQ
Cloudflare DNS questions we are asked
- Will proxying break our mail or phones?
- It would, which is why mail, SIP and VPN records are kept DNS-only. Only HTTP and HTTPS hostnames are proxied.
- How long does a nameserver change take?
- Delegation typically completes within a few hours. Record TTLs are lowered beforehand so any correction propagates quickly.
- Is DNSSEC always advisable?
- Where the registrar supports DS records, yes. It prevents forged answers, and the main risk — a broken chain during migration — is managed by sequencing the change.
Related
Other security & dns platforms
Cloudflare DNS is referenced to describe engineering capability. All trademarks and product names are the property of their respective owners; no partnership or endorsement is implied.
Ready to scope the work?
Share your environment and objectives. You will get an engineering response covering scope, approach and considerations.