What is Anycast DNS?

Anycast DNS advertises the same authoritative service from many locations. How Cloud DNS uses 210+ servers and DDoS-protected authority.

Unicast DNS has a home address. Anycast DNS has a home announcement: the same nameserver addresses are reachable from many places, and the network carries the resolver to a nearby available path.

The lookup should not have a region

If both of your nameservers sit in one network path, a congestion or attack on that path is a zone outage. Cloud DNS answers from 210+ Anycast servers so the authority is not a pair of VMs with pretty NS names.

DDoS is a DNS problem first

Attackers flood authority because it is a small target with a large blast radius. DDoS-protected Anycast is how the zone stays reachable when that happens.

Anycast does not replace records

You still enter A, AAAA, MX and CNAME. Anycast is how those answers are served. GeoDNS, weights and health checks still decide which answer a given resolver receives.

IPv6 and vanity NS

Authority should speak IPv6 as well as IPv4. Vanity nameservers can be branded while the same Anycast network answers underneath.

Frequently Asked Questions

No. Cloud DNS is authoritative for zones you host, not a public recursive resolver.

No. TTL is a record attribute. Cloud DNS still supports a one-second minimum when you need it.

A zone has one set of nameservers. Delegate a subzone if you must split authority.

Run this on Cloud DNS.

Get started with our Management Console in less than 2 minutes, or connect with an expert to supercharge your business today.