In-region logging on Enterprise.Details
Secure Domains
Architecture

How the platform works.

DNS Armor™ is one stack with three layers: security, DNS and traffic intelligence. Every query passes through the same layers, and every deployment model runs the same platform.

  • 3 layers, one policy model
  • 4 deployment models
  • Region-pinned data
Overview

Three layers, one control plane.

Every query passes through all three. They share one portal, one policy model and one audit trail.

  1. 01

    Security layer

    Decides whether a destination is safe to reach.

    • AI detection
    • Threat intelligence
    • Domain classification
    • Policy engine
    • RPZ and DNS filtering
  2. 02

    DNS layer

    Answers queries, recursive and authoritative.

    • Recursive DNS
    • Authoritative DNS
    • DNSSEC signing and validation
    • DoH and DoT
  3. 03

    Traffic intelligence

    Sends users to the healthiest, closest endpoint.

    • Geo steering
    • GSLB
    • Health checks
    • Performance routing
Layer 01

Security layer: decide before you connect.

Each lookup is checked against threat intelligence, AI behaviour models and your own policy before an answer is returned. A blocked domain never resolves, so the connection is never made.

AI detection

Behavioural models flag DNS tunnelling, DGA domains and slow exfiltration that lists miss.

Built-in intelligence

Threat, web-filtering and application feeds are applied at resolution time.

Classification and scoring

Every domain gets a category and a threat score before your policy decides.

Scheduled policies

Cloud Policies activate on a schedule; Local Rulesets make explicit allow and block decisions.

RPZ in and out

Ingest external RPZ feeds on a sync schedule and export your own.

Layer 02

DNS layer: recursive and authoritative, one platform.

DNS Armor Protect™ resolves your users’ queries; DNS Armor Resolve™ answers for your own domains. Both are signed, validated and encrypted in transit.

User or device

Recursive resolver

DNS Armor Protect™

Authoritative DNS

DNS Armor Resolve™

Signed answer

DNSSEC-validated

Validated recursion

Recursive resolution with DNSSEC validation against spoofing and cache poisoning.

Authoritative hosting

Your zones hosted with automated DNSSEC signing.

Key rotation handled

KSK and ZSK lifecycle and rotation are managed for you.

Encrypted transport

DNS over HTTPS and DNS over TLS, enforced per tenant.

Split horizon

Bypass Domains keep internal namespaces resolving on-premises.

Layer 03

Traffic intelligence: send users to the healthiest endpoint.

Resolve steers each answer by geography, source network, health and latency. Unhealthy endpoints leave the response set automatically.

Query for app.example.com

Resolve steering

Dubai endpoint

Healthy · closest

Frankfurt endpoint

Healthy · standby

Singapore endpoint

Failing health check · removed

Geo and source-IP steering

Answer each query with the endpoint that suits where it came from.

Health checks

HTTP, TCP, ICMP and custom probes decide which endpoints stay in answers.

Priority-group failover

Traffic moves to the next group automatically when a group fails.

Answer ordering

Round-robin or latency-ordered answers across healthy endpoints.

EDNS Client Subnet

Finer location for users behind large shared resolvers.

Deployment

Deploy it your way.

Cloud delivered, or on your own hardware.

Same policy, same portal.

Local Resolver appliances keep internal resolution on your premises while cloud policy follows every device.

Deployment models

Run it the way your network and regulator require.

The same platform and policy model in every option. Choose where enforcement happens and where data lives.

Your premises

Networks & devices

DNS Armor cloud

Cloud delivered

Point your networks and devices at DNS Armor. Nothing to install on site; roaming devices use the Endpoint Agent.

Best for fast rollout and distributed teams.

Your premises

Devices

Local Resolver

DNS Armor cloud

Local Resolver appliance

A virtual appliance (ESXi, Hyper-V or KVM, in high-availability pairs) in proxy mode or full local mode, with an Active Directory connector.

Best for per-user visibility and internal namespaces.

Your networks

Your chosen region

Dedicated tenant

Private cloud

A dedicated tenant with dedicated storage, in the region you choose, operated by Secure Domains.

Best for regulated sectors that need isolation without running infrastructure.

Your premises

Devices

Resolvers in your DC

Management portal

On-premises

Resolvers and agents inside your own data centre, managed from the DNS Armor portal, licensed to your scale.

Best for government and critical infrastructure.

Data flow and residency

Where queries are processed and logs are stored.

Two tracks, stated plainly. Frankfurt is the automatic service plane for online self-signup only; Enterprise keeps both planes in the region you choose.

Self-service (online signup)Served automatically from our Frankfurt, Germany service plane. DNS logs are archived in the region you choose at signup. Applies to DNS Armor Protect™ and DNS Armor Resolve™ accounts created online.
EnterpriseService plane and logging plane together in the region you choose, so queries are processed and logs are stored in the same jurisdiction. Dedicated storage, private cloud or on-premises available.
Data residency by plan
PlanSelf-service (online signup)Enterprise
ProductsDNS Armor Protect™ and DNS Armor Resolve™Same, licensed independently
Service planeFrankfurt, Germany, for self-signup accounts onlyIn the region you choose
Logging plane / log archiveRegion chosen at signupSame region as the service plane
StorageShared service plane, per-account tenantDedicated per customer or tenant; private cloud or on-prem available
Resilience

Built to keep answering.

DNS is the first dependency of every application, so the platform is designed around redundancy at each layer.

Regional assignment

Each customer is assigned to a region and served by healthy nodes there, across 52 data centres in 32 countries.

Health-checked GSLB

Continuous probes drive priority-group failover, so traffic moves away from a failing endpoint without manual action.

High-availability appliances

Local Resolver appliances run in HA pairs on ESXi, Hyper-V or KVM, so on-site resolution survives a host failure.

Map DNS Armor™ to your architecture.

A solutions engineer will walk through the deployment model and residency set-up that fits your network and regulator.