Skip to content

Hidden primary

With a hidden primary you maintain the zone on your own nameserver, but the regfish nameservers stay in charge facing the world. regfish fetches the zone data from your server and distributes it over its own anycast infrastructure. The page itself calls the service one for advanced users, and that is accurate.

Domains → your domain → Advanced → Hidden primary, direct address: dash.regfish.com/my/domains/<tld>/<sld>/hpns

The hidden primary settingThe hidden primary setting

Once activated, regfish fetches the zone from your nameserver via AXFR zone transfer. Your firewall has to allow the fetch address named on the page on TCP port 53; without that clearance no transfer happens.

From then on the zone is maintained on your server. The DNS records in the dash are no longer the source.

Authoritative NSHidden primary
Who answers to the worldYour nameserversThe regfish nameservers
Where the zone is maintainedOn your serversOn your primary
regfish anycast and DDoS shieldingNoYes

So the hidden primary is the way to combine your own zone management with the resilience of the regfish infrastructure.