Skip to content
A Akamai Security Reference

Product deep dive

Edge DNS & DNS Security

DNS is the first request of every session and a single point of failure for everything downstream. Akamai splits the problem into authoritative resilience (Edge DNS, DNS Shield, GTM) and outbound resolution security (protective/recursive DNS).

The DNS risk surface

ThreatMechanismPrimary control
Authoritative DNS DDoSQuery flood or random-subdomain (water torture) flood exhausting nameserver capacityMassively distributed anycast authoritative DNS
Cache poisoning / spoofingForged UDP answers accepted by a resolverDNSSEC validation, source-port randomisation, 0x20 encoding
Domain hijackRegistrar account compromise or unauthorised NS/DS changeRegistry lock, MFA on registrar, change alerting
Zone data leakageOpen AXFR, over-broad TXT records, internal hostnames in public zonesTransfer ACLs, zone hygiene reviews
Subdomain takeoverDangling CNAME to a deprovisioned cloud resourceContinuous record inventory and validation
Malware C2 / exfiltration over DNSOutbound resolution to attacker-controlled domains, data tunnelled in labelsProtective/recursive DNS with threat intelligence

Edge DNS — authoritative resolution

Edge DNS is a fully managed authoritative DNS service running on Akamai's globally distributed anycast network. Its defining property for security is architectural: attack traffic aimed at your zone lands on hundreds of points of presence simultaneously, so no single site absorbs the full load. A flood that would obliterate a pair of self-hosted nameservers is diluted across the platform.

Core capabilities

DNSSEC operational notes

DNSSEC gives resolvers cryptographic proof that an answer came from the zone owner and was not modified. The failure modes are almost always operational rather than cryptographic:

Resilience patterns

DNS Shield

DNS Shield places a dedicated caching and filtering tier between recursive resolvers and authoritative infrastructure. The value is twofold: it absorbs abusive query patterns (particularly random-subdomain floods that are uncacheable by design) before they reach authoritative servers, and it shortens the resolution path from major ISP resolver networks, improving both latency and reliability for real users.

Global Traffic Management

GTM is DNS-based load balancing and failover: liveness and performance checks decide which answer a resolver receives. Security relevance:

Remember the constraint: DNS-based steering is only as fast as the TTL and as accurate as the resolvers' behaviour — some resolvers and clients ignore TTLs. Plan for a tail of traffic that continues to hit the old answer.

Protective / recursive DNS — the outbound direction

Everything above protects inbound resolution of your names. Protective DNS addresses the opposite direction: what your users, servers and IoT devices resolve on their way out. Because virtually all malware performs DNS lookups — for command-and-control, for payload staging, or to tunnel stolen data — the recursive resolver is a uniquely efficient enforcement point.

What it blocks

Deployment considerations

DNS security checklist

  1. Inventory every zone and every record; hunt dangling CNAMEs monthly.
  2. Registry lock plus MFA at the registrar; alert on NS and DS changes.
  3. Authoritative DNS on anycast with capacity far beyond your peak; consider multi-provider.
  4. DNSSEC signed with managed key rollover; monitor signature expiry externally.
  5. Disable open AXFR; restrict transfers to known secondaries.
  6. CAA records to constrain which CAs may issue for your domain.
  7. Deliberate TTL policy documented per record class.
  8. Protective recursive DNS outbound, with port 53 egress locked down.
  9. Monitor query volume, NXDOMAIN ratio and response codes; alert on deviation.

Reference documentation compiled from Akamai TechDocs, Akamai blog/newsroom material and Cloudflare Learning Center fundamentals. Product behaviour and limits change — validate against current vendor documentation before production use.