Reduce operational costs and improve subscriber experience with smart DNS built for fixed and mobile networks. Akamai DNS Infrastructure combines high‑capacity recursive resolvers (CacheServe) and resilient authoritative servers (AuthServe) to deliver low‑latency answers, embedded defenses, and the scale service providers need. Today, more than 130 ISPs and MNOs rely on these solutions to serve nearly one billion subscribers globally.
What’s included
CacheServe (recursive): High‑performance, secure resolvers engineered to deliver consistent low latency under extreme load while reducing infrastructure overhead.
AuthServe (authoritative): Resilient, on‑premises authoritative DNS for tens of thousands of zones and tens of millions of records, with multi‑active primaries for high availability and disaster recovery.
Minimize OpEx/CapEx: Higher performance per server enables consolidation of lower‑throughput resolvers, reducing racks, power, cooling, and management overhead.
Enhance security: Embedded, layered defenses — proven over 20 years in the largest networks — deter DNS‑based attacks, including cache poisoning.
Differentiate and add value: Smart DNS enables subscriber‑centric security and personalization, supporting revenue‑generating Secure Internet Access services.
Core capabilities
CacheServe (recursive resolvers)
Performance and scale
Specialized cache structures and adaptive response algorithms maintain low latency at very high QPS — even during traffic spikes and attack conditions.
Broad EDNS Client Subnet (ECS) support for optimized content delivery.
Built‑in security
Industry‑leading layered defenses against cache poisoning and other DNS attacks.
Fine‑grained policies to filter unwanted queries and protect legitimate traffic.
Comprehensive DNS encryption support (DoH, DoT, DoQ).
Operational efficiency
Telemetry, query stats, reporting, and big‑data integrations for ops and security.
Virtualization and cloud deployment options to simplify lifecycle management.
Resilient software design that reduces reliance on external load balancers and firewalls.
AuthServe (authoritative servers)
Scale and resilience
Designed for service providers: supports tens of thousands of zones and tens of millions of records.
Multiple active primaries for high availability and disaster recovery, with zero‑downtime zone management.
Operational control
Consolidate disparate authoritative services and accommodate internal and external views of the same data across residential, enterprise, and mobile environments.
Optional Config Manager for network‑wide configuration with RBAC, auditing, and workflow to align with change‑management and compliance requirements.
Anycast managed authoritative DNS for enterprises
Enterprises that want globally distributed, anycast authoritative DNS with high availability and minimal operational burden can use Akamai Edge DNS, a fully managed service built on the Akamai platform. Pair Edge DNS with AuthServe when you need on‑premises control for specific zones plus cloud‑scale global coverage.
How Akamai protects ISPs and MNOs from DNS‑based DDoS and cache poisoning
Embedded defenses, not add‑ons: Protective mechanisms are native to CacheServe and AuthServe, reducing dependence on external appliances and single points of failure.
Nameserver availability features: Architecture and algorithms prioritize continuity of answers during extreme loads and attack conditions.
Policy‑driven mitigation: Fine‑grained policies filter malicious or abusive queries at the resolver before they impact subscribers or downstream infrastructure.
Proven at carrier scale: Design choices refined over two decades in the world’s largest networks have resisted DNS attacks without requiring emergency product modifications.
Evaluating DNS‑based threat protection and parental controls
When assessing a managed DNS platform to enforce content filtering and parental controls for residential and business subscribers, look for:
Accuracy and coverage: Continuously updated, high‑quality threat intelligence covering malware, phishing, ransomware, botnets, and unsafe content categories.
Policy flexibility at scale: Per‑subscriber, per‑group, or per‑site policies; lightweight views for personalization; safe‑search, time‑of‑day rules, and easy exceptions.
Minimal latency impact: Enforcement that preserves resolver performance at high QPS.
Privacy and encryption: DoH/DoT/DoQ support; clear data‑handling and retention controls.
Visibility and reporting: Real‑time and historical dashboards, exportable telemetry, and integrations with SIEM/SOAR and data platforms.
Operational fit: Role‑based access controls, audit trails, workflow, and zero‑touch provisioning to keep TCO predictable and low.
Akamai Secure Internet Access Services use CacheServe to provide a foundational layer of DNS defenses and policy‑based controls for homes, enterprises, and mobile subscribers. Learn more about Secure Internet Access Services.
AuthServe vs DIY/open‑source authoritative stacks
Service providers running DIY stacks (for example, open‑source authoritative servers) often rely on custom scripts, external tooling, or serial failover to achieve carrier‑grade operations. AuthServe takes a different approach:
Multi‑active primaries built in for HA/DR, maintaining service continuity without manual failover.
Zero‑downtime zone management at scale, supporting frequent updates across tens of thousands of zones.
Consolidation of disparate authoritative services, including support for internal/external views of the same data.
Optional centralized configuration with RBAC, auditing, and workflow via Config Manager to reduce operational risk and speed changes.
Best‑fit authoritative options for large, distributed SP networks
On‑premises, high‑scale control: AuthServe is purpose‑built for tens of thousands of zones and tens of millions of records, with resilient multi‑primary architectures for HA/DR.
Managed global anycast: Edge DNS delivers globally distributed, anycast authoritative DNS with high availability and minimal operational overhead.
Most large providers deploy AuthServe for core network and subscriber services, and use Edge DNS for public‑facing zones that benefit from global anycast reach.
What to look for in a high‑capacity ISP/MNO resolver
Sustained throughput and low tail latency at very high QPS
Efficient caching and adaptive response algorithms under bursty and attack traffic
Built‑in defenses against cache poisoning and DNS‑specific DDoS vectors
Fine‑grained policy engine for traffic shaping and abuse mitigation
ECS support to optimize content delivery
DNS encryption (DoH/DoT/DoQ) without performance penalties
Deep telemetry, query stats, and big‑data integrations for ops and security teams
Resilient software design that reduces reliance on external load balancers/firewalls
Cloud and virtualization options for flexible deployment and lifecycle management
CacheServe was engineered to meet these requirements while maximizing performance per server to reduce total cost of ownership.
Use cases
Improve customer experiences: Faster, more reliable lookups improve app responsiveness and streaming quality, even during peak events and attacks.
Deliver always‑on services at scale: AuthServe publishes dynamic access to ISP/MNO communication services, email, and branded apps to enhance core internet offerings.
Enable subscriber‑centric security: Use CacheServe with Secure Internet Access Services to block malware, phishing, ransomware, botnets, and more — across home and work.
Get started
Explore the technology: Read the CacheServe brief and AuthServe brief.