IPv6 DNS: publishing AAAA without lying

Publish AAAA only for endpoints that speak IPv6, serve authority over IPv6, and health-check both families on Cloud DNS.

IPv6 is a record and a transport. Publishing AAAA for an origin that only speaks IPv4 breaks dual-stack clients. Not publishing AAAA when Cloud CDN can deliver over IPv6 leaves performance on the table.

Only publish what accepts packets

Add AAAA for dual-stack endpoints you can probe. Cloud DNS will happily serve a lie if you enter one.

Authority over IPv6

Nameservers should be reachable over IPv6 as well as IPv4. Cloud DNS Anycast nameservers support both.

Do not let v4 and v6 maps disagree

If GeoDNS sends IPv4 to region A and IPv6 to region B, you will debug ghosts. Design the maps together.

CDN clients versus origin

The edge can speak IPv6 to users while origin pull stays IPv4. That is normal. Do not publish AAAA for the origin just because the CDN is dual-stack.

Frequently Asked Questions

Not for that origin. Cloud CDN can still deliver IPv6 to clients on the public hostname.

Yes. Sign the zone, including AAAA records.

Vanity nameservers are supported. Include AAAA glue where the parent requires it.

Run this on Cloud DNS.

Get started with our Management Console in less than 2 minutes, or connect with an expert to supercharge your business today.