Features Security Architecture Console Contact Us

HexaDNS

Ultra Fast Policy-Driven Cache Resolver

Enterprise-grade DNS infrastructure for telecom operators and ISPs. Carrier-class caching, policy-driven resolution, and real-time security — all from a single platform.

<1ms
Cache Response Time
1M+
Queries per Second
7+
DDoS Protection Layers
100%
API-Driven Automation
Core Platform

Built for Scale, Designed for Control

A complete DNS-as-a-Service infrastructure with high-performance caching, multi-tenant isolation, and programmable policies.

High-Performance Caching

In-memory caching engine delivering sub-millisecond response times. Optimized for millions of concurrent queries.

Multi-Tenant Virtual Servers

Isolated DNS configurations per destination IP:port. Each virtual server maintains independent policies, lists, and resolution rules.

Policy-Based Resolution

Domain and list-based access control with flexible actions: DROP, NXDOMAIN, REFUSED, REDIRECT (A/AAAA), and SERVFAIL per policy rule.

Category-Based Filtering

Define block and redirect rules per content category — malware, adult, social media, gambling — without upstream DNS changes.

List Management

Support for DOMAIN and SHA1-hash based blocklists. Add, delete, and manage lists via API with real-time capacity tracking.

API-First Design

RESTful management and client APIs with full documentation. Complete automation via API keys with key/secret authentication.

Parental Control

Subscriber-level content filtering with age-appropriate profiles. Protect children from harmful content through DNS-based policy enforcement.

Safe Internet

Operator-grade Safe Internet service with DNS-level content blocking. Enable clean browsing experiences across your entire subscriber base.

Regulatory Compliance

Full compliance with national access blocking and content filtering regulations. Ready-to-deploy for ISP and telecom regulatory requirements.

Security

Enterprise-Grade DNS Protection

Seven layers of DDoS and abuse protection built into the core engine. Real-time threat mitigation without external dependencies.

NXDOMAIN Flood Protection

Per-client and per-domain rate limits against NXDOMAIN attack floods targeting your resolver infrastructure.

Amplification / Reflection Defense

Response rate limiting per client IP prevents your DNS infrastructure from being weaponized in reflection attacks.

Query Flood Protection

Token bucket rate limiting with configurable burst allowance. Absorb traffic spikes while blocking sustained attacks.

Cache Poisoning Hardening

Built-in protections against cache poisoning attempts with randomized source ports and transaction IDs.

TCP Flood Protection

Connection limits per client and globally to prevent resource exhaustion from TCP-based DNS floods.

Malformed Packet Handling

Graceful handling and rejection of malformed DNS packets that could exploit parser vulnerabilities.

Architecture

Designed for Carrier-Grade Networks

Scalable query processing with upstream deduplication, destination-IP routing, and horizontal scaling.

Scale Without Limits

HexaDNS is engineered for telecom-scale deployments with multi-worker query processing and intelligent upstream resolution.

  • Multi-worker query processing with upstream deduplication
  • Destination-IP-based virtual server routing
  • Forwarding and full resolver modes
  • In-memory cache store for ultra-fast lookups
  • Horizontal scaling via load-balanced containers
  • IPv4 (/8-/32) and IPv6 (/16-/128) client tracking
Clients
DNS queries over UDP/TCP
HexaDNS Engine
Cache + Policy Engine + Workers
Cache Hit
<1ms response
Cache Miss
Upstream resolution
Management API
REST API + Database
Web Console
Web-Based Dashboard
Management Console

Full Visibility, Total Control

Modern web-based console with RBAC, real-time monitoring, and comprehensive DNS reporting.

Live Dashboard

Real-time DNS statistics, hit ratios, query types, and system health at a glance.

RBAC & Users

Granular role-based access control with custom permissions, user management, and audit logs.

DNS Reports

Historical data with top domains, top clients, query type breakdowns, and daily trends.

Security Monitor

Detailed security hit tracking, attack metrics, and real-time threat visibility.

System Metrics

CPU, memory, disk, and network monitoring with historical graphs and hardware specs.

Virtual Servers

Configure and manage isolated DNS instances with per-server listener and policy settings.

API Keys

Manage API access with key/secret pairs for programmatic integration and automation.

Access Logs

Complete audit trail with user activity tracking, change history, and compliance support.

Global Network

Anycast DNS at the Edge

Distributed HexaDNS nodes across multiple regions deliver ultra-low latency DNS resolution through Anycast routing.

Anycast
Global DNS
HexaDNS-01 Frankfurt
HexaDNS-02 Istanbul
HexaDNS-03 New York
HexaDNS-04 Singapore
HexaDNS-05 São Paulo
HexaDNS-06 Dubai
HexaDNS Node
Anycast Cloud
BGP Anycast Route
Deployment

Deploy Anywhere

Flexible deployment options from bare-metal appliances to fully containerized cloud environments.

Docker & Kubernetes

Production-ready Docker Compose and container orchestration with Nginx load balancing.

Bare-Metal Appliance

Dedicated hardware deployments in multiple capacity tiers — from branch offices to core network.

Virtual / Cloud

VMware, KVM, Hyper-V, and public cloud platforms with elastic scaling and cost efficiency.

Ready to Upgrade Your DNS?

See how HexaDNS can transform your network's DNS infrastructure with carrier-grade performance and security.

Request a Demo Learn More