Concepts

Why CNX's DNS service works the way it does.

  • CNAME flattening

    Why the zone apex can't hold a CNAME, and how CNX resolves the target for you.

  • DNSSEC

    Why every zone is signed automatically, and what needs your action versus CNX's.

  • The compliance evidence package

    What's in the daily compliance evidence package and why it exists.

  • In-bailiwick nameservers

    Why in-bailiwick nameservers require glue records, and how glue removes an otherwise separate nameserver-address lookup from the cold DNS path.