"After switching to DNSBOX appliances, we've found fewer cases of human error and better tracking of changes..."
Teddie Strother, Senior Systems Administrator, University of Michigan-Dearborn, USA
"I love the DNSBOX solution. It's working really well for us – much more stable and reliable than our previous virtual solution"
James Montoya, USGS (US Geological Survey) - Colorado, USA
"I’ve worked with a lot of DHCP appliances, DNSBOX is by far the easiest I’ve ever dealt with"
Anthony Grande, Senior Systems / IT Network Administrator, Phoenix Suns, USA
"Every question, concern and need has been addressed in a timely manner"
Ed Buonocore, Systems Manager, US Federal Probation D/NJ, NJ, USA
"DNSBOX met our needs for security, ease of use and cost-effectiveness"
Rupesh Halai, Parliamentary and Health Service Ombudsman (PHSO), UK

Protect Against Cache Poisoning with DNSSEC

Many organisations want to introduce DNSSEC to protect against cache poisoning which can result in your users being misdirected to malicious websites and/or disrupt services that rely on DNS such as email and VOIP.

But implementing and managing DNSSEC can be complicated, costly and time-consuming:

  • All your zones need to be signed for DNSSEC to be effective – a big task for large networks
  • DNSSEC keys need to be stored securely so that they cannot be changed maliciously
  • Keys also need to be periodically updated – known as ‘key rollover’.
  • Additional DNSSEC steps in DNS resolution may introduce unwanted latency

Key rollover is particularly complex and requires very careful administration. If you get it wrong, keys which are no longer valid remain cached in other DNS servers around the world or are not synchronised with your own upstream servers. In such cases, clients using DNSSEC would be unable to resolve your records. With lots to know and manage, manual key rollover is incredibly error-prone.

DNSSEC-Screenshot-smYou need a solution that, like DNSBOX:

  • Automates DNSSEC key management and rollover
  • Automates zone signing for rapid implementation
  • Makes it easy to store DNSSEC keys securely
  • Uses a high performance resolver to mitigate the extra latency of DNSSEC requests

Next: Microsoft Integration >

Because DNSBOX is versatile and scalable, our customers around the world come in all shapes and sizes. Some want to simplify, control and protect their DDI services, others just want to solve a specific DNS or DHCP headache.

How can we make your visit easier?


Give us a few details about your requirement and we'll make your life easier by serving the most relevant information.
I work in a...
I prefer to read...
GO