AnyZone
Secondary DNS, hands-off

Your zone, replicated. Your servers, replaceable.

Point an AXFR at us and get three anycast nameservers that keep serving your zone even when your primary is down, gets rebuilt, or moves clouds. No dashboard to babysit — just a link that tells you exactly what's happening.

3Nameservers
60sSync interval
0Passwords
Your zone, as we'll see it
$ORIGIN your-domain.com.
$TTL 3600
ownerTXT
contactTXT
primaryNS
primaryA

Set up secondary DNS

We'll email you a single link. That link is your access — no account to create.
We'll email a link to verify you own this domain, then walk you through the rest.

How it works

Four automatic steps. You only ever touch two of them.
01

Verify

Confirm your email, then drop a TXT record on your domain. We check for it automatically.

02

Connect

We tell you which addresses to allow — a plain IP allow-list, or TSIG if your provider supports it.

03

Transfer

Our nameservers pull your zone directly, on their own schedule — no middleman holding the data hostage.

04

Forget about it

We keep pulling. If a transfer ever fails, we keep serving your last good copy — no downtime, no page.

Common questions

The ones people actually ask before they sign up.

Do I need to move my domain to AnyZone?

No. Your existing primary DNS stays exactly where it is. AnyZone only adds redundant secondary nameservers — you keep full control of the zone itself.

What if my provider doesn't support TSIG?

That's fine — most providers support a plain IP allow-list instead, and we tell you exactly which addresses to permit. TSIG is offered as an optional extra layer, never a requirement.

What happens if a transfer fails?

Nothing dramatic. We keep retrying quietly and keep serving your last successful copy the whole time. You'll only hear from us if it's been failing for a while, so you can go look into it.

Does this work if my primary doesn't support outbound zone transfers at all?

Some hosted DNS providers (usually free tiers) don't allow any third party to AXFR from them, under any authentication method. If that's your situation, check our docs for a workaround, or just get in touch.