Authoritative DNS Proxy
Authoritative DNS Proxy proxies DNS queries through Alibaba Cloud infrastructure, providing DDoS protection, access acceleration, and disaster recovery without complex migration.
Benefits
DDoS caching: Caches DNS responses to protect authoritative servers from DDoS attacks and reduce load.
Access acceleration: Routes queries through Alibaba Cloud's global POPs for faster, nearby resolution.
Service backup: Serves cached data if your authoritative server fails, reducing downtime.
Cost savings: Reduces bandwidth and costs for self-hosted DNS.
Limits
Create Authoritative Domain Name
Switch to the Authoritative DNS Proxy tab.
Click Create Authoritative Domain Name, and configure the parameters.
Parameter
Description
Authoritative Zone Name
The service domain name that requires the feature.
Service Instance
Select and attach a purchased instance.
NoteIf the list is empty, purchase an instance first.
Running Mode
Proxy Mode: Returns cached records for DNS queries. On cache miss, queries the origin server, returns the result, and caches it.
Penetration: After receiving a DNS query, the system always forwards the query to the origin server for resolution instead of using cached data. After getting the result, the system stores it in the cache.
NotePenetration Mode is visible only to users added to the allowlist.
Minimum TTL Period of Back-to-origin Cached Data
Maximum TTL Period of Back-to-origin Cached Data
Cache TTL range for DNS records, in seconds. Valid values: 30 to 86400.
NoteAfter the feature is enabled, local DNS query TTL follows Authoritative DNS Proxy settings. If a carrier forcibly extends the TTL, contact the carrier.
Back-to-origin DNS Query Protocol
Sends DNS queries to the authoritative server over UDP.
NoteCurrently, only UDP is supported.
EDNS Client Subnet: If your authoritative server supports EDNS, enable this option. During recursive queries, if the local DNS also supports EDNS, Authoritative DNS Proxy forwards the client's egress IP from the local DNS query to your origin server.
Origin DNS Servers
One or more origin DNS server addresses. The default port is 53. Change the port number as needed to match your origin DNS server.
Query cached data
Caching mechanism
If the origin server uses smart DNS, origin-fetch records for the Authoritative Zone Name are cached according to the matched rule.
Authoritative DNS Proxy uses a cache reserve mechanism. Unexpired records are served directly from cache. When a record expires, the next query triggers an origin fetch and updates the cache. If the origin fetch fails, expired data continues to be served until the record is purged due to infrequent requests.
Procedure
Switch to the Authoritative DNS Proxy tab.
For the target domain, click Cached Data in the Actions column.
NoteCached Data supports three line types: carrier, outside mainland China, and Alibaba Cloud.
Carrier lines: categorized by China Telecom, China Unicom, and China Mobile. Select a province on the map to view.
Outside mainland China: categorized by continent (Asia, Europe, North America, South America, Africa, Oceania). Select a country to view.
Alibaba Cloud lines: Cached Data is displayed by region.