Skip to content

Security & DNS

Cloudflare DNS

Authoritative DNS on a global anycast network with DNSSEC, proxying and rapid propagation, used where resolution must stay fast and available under attack.

Anycast authoritative DNS point of presence with resolver servers and a global network node map behind
SYSTEM ACTIVE
ANYCAST DNS · Cloudflare DNS

Capabilities

What we implement

  • Zone migration with a record-by-record audit
  • Proxy versus DNS-only decisions per record
  • DNSSEC enablement and registrar DS records
  • TTL strategy for planned cutovers

Security

How it is hardened

  • DNSSEC signing and registrar lock
  • Account MFA and scoped API tokens
  • CAA records and audit logging of zone changes

Editions & pricing

Cloudflare DNS editions and vendor pricing

Vendor list prices for the editions we deploy. Deployment, migration, hardening and support are quoted separately by Techno Trader PK — they are never bundled into these figures.

Cloudflare DNS editions, licensing unit and vendor list price
EditionLicensed byVendor list price
Free authoritative DNSIndicative; paid plans add WAF and performance features.per domain / month$0

Prices are checked against the vendor's published price list. Last verified 10 Sept 2026. Vendor list prices exclude tax and can change without notice.

Licence cost is only part of the number. Add deployment, migration and ongoing support to see the real figure for your environment.Get a scoped quote

Architecture

Authoritative DNS on anycast

Zones are migrated record by record, signed with DNSSEC and controlled with TTL discipline so cutovers are predictable.

  1. 01 · Zone migration

    Record auditImport and diffNameserver delegation

    The imported zone is compared against the source before delegation changes.

  2. 02 · Resolution

    Anycast networkDNS-only recordsProxied records

    Mail, SIP and other non-HTTP records stay DNS-only; only web traffic is proxied.

  3. 03 · Integrity

    DNSSEC signingDS record at registrarCAA records

    Signing is completed at the registrar, not left half-enabled.

  4. 04 · Control

    Account MFAScoped API tokensChange audit log

    Zone changes are attributable and API access is limited to what automation needs.

FAQ

Cloudflare DNS questions we are asked

Will proxying break our mail or phones?
It would, which is why mail, SIP and VPN records are kept DNS-only. Only HTTP and HTTPS hostnames are proxied.
How long does a nameserver change take?
Delegation typically completes within a few hours. Record TTLs are lowered beforehand so any correction propagates quickly.
Is DNSSEC always advisable?
Where the registrar supports DS records, yes. It prevents forged answers, and the main risk — a broken chain during migration — is managed by sequencing the change.

Related

Other security & dns platforms

Cloudflare DNS is referenced to describe engineering capability. All trademarks and product names are the property of their respective owners; no partnership or endorsement is implied.

Ready to scope the work?

Share your environment and objectives. You will get an engineering response covering scope, approach and considerations.