Authoritative cluster
Two authoritative groups (ns1, ns2) carried by three mutually independent network providers, all anycast — 23 nodes in total, powering highly available, millisecond-level DNS responses worldwide. A further 3 nodes (Hong Kong ×2, Singapore) form the accelerated line for mainland China.
Data sync
The primary lives in Singapore, hidden behind the protection layer, never answering the public internet; every edge node long-polls for changes — a record edit reaches all nodes within seconds. Edges hold only encrypted replicas and no plaintext ever lands on their disks; each node answers from a resident in-memory snapshot, and data swaps never interrupt service.
Authoritative engine: dnsd
In-house authoritative engine: every zone lives in a resident in-memory snapshot, the query hot path is lock-free, and data swaps never pause answering. The network currently answers about 4.2 million queries a day (as of 2026-09).
Front-line defense: dnsway
An in-house defense layer in front of every node's authoritative responder: reputation-tiered rate limiting, UDP amplification mitigation (response-size clamping for unverified sources plus TC challenges forcing genuine-source TCP), and automatic banning of anomalous query patterns. It exists to stop people using free DNS as an attack reflector — normal queries never notice it.
Split-horizon
Answers vary by the querying client's location (GeoIP, EDNS Client Subnet supported): 19 preset routes (Mainland China / outside Mainland China / HK-MO-TW / US-JP-KR-SG + CN Telecom / Unicom / Mobile / CERNET + six continents), plus user-defined IP-range routes. Routes are purely an answer-steering dimension — they classify where the query comes from, not where data lives: all authoritative data is stored in Singapore only.
Dogfooding
anyns.io and n.ht themselves resolve on this cluster — one dig verifies it. The cluster served its builders for a long time before opening to anyone else.