lbreeze

Twelve places to answer from. One place to change it.

Our nameservers are anycast: every one of them answers for every zone, and a resolver reaches whichever is nearest and up. You edit a record once, in the same panel as your site and your mail, and there is no region to choose because DNS is not put anywhere in particular.

See DNS
ONE ADDRESSns1 … ns4nearestansweringofflinerouted aroundansweringsame zoneansweringsame zoneevery nameserver serves every zoneso losing one is uneventful rather than an outagetwelve points of presence · four regions

Where the nameservers are

Twelve points of presence, four regions.

This is the anycast DNS footprint: the places a resolver can get an answer from. Every one of them serves every zone, so the list is not a menu you pick from — it is the set of places your records already are.

Americas

  • San Francisco
  • New York

Europe

  • London
  • Amsterdam
  • Frankfurt
  • Paris
  • Helsinki
  • Sofia

Middle East & Africa

  • Dubai
  • Johannesburg

Asia Pacific

  • Tokyo
  • Sydney

What that buys you

Six consequences, not six features.

None of these were added on top. They follow from every nameserver holding every zone, which is a decision about how the thing is built rather than a list of things it does.

No region to pick

You are never asked where your DNS should live, because it does not live in one place. That question simply does not come up at order time or afterwards.

Losing one is uneventful

Every nameserver answers for every zone. One going away is a routing change rather than an incident, and nothing about your zone has to be moved or re-delegated.

Your change is instant on our side

The edit reaches our nameservers straight away. What you actually wait for is the TTL on the old record expiring in other people's caches — which is why you lower it the day before a planned move.

A failed change is not reported as saved

If a record cannot be pushed it stays marked pending and is retried, rather than showing a green tick and doing nothing.

DNSSEC is a switch

Turn it on and signing is handled. If the domain is registered with us the registrar side is done too, so there is nothing to hand-copy between two panels in the wrong order.

We do not publish a latency figure

Because the honest one depends on your visitors rather than on us. What we can tell you is where the answers come from, which is the list above.

On a cloud server

Between your own machines

The network parts of a virtual machine that people usually find out about after they have bought one.

  • A private network Attach machines to one and keep the traffic between them — and to your database — off the public internet entirely, rather than firewalled on it.
  • IPv6 where the node serves it Where a location has it, your machine gets it as a matter of course rather than as a support request.
  • A public IPv4 address where the plan includes one If yours does not, ask. It is an allowance rather than a hard limit of the platform.
  • HTTP/3 where it truly works Enabled where the server can genuinely serve it and refused where it cannot, because half-enabling it takes every site on the machine down with it.
  • TLS terminated at the edge Certificates issued and renewed there for every site and every mail domain, with rate limiting in the same place rather than in six different ones.
PRIVATE NETWORKwebpublic addressworkerno public addressdatabaseno public addressthe internetonly what you expose is exposed — the rest talks over theprivate side and never appears on the public one

How the estate is split

Different jobs, deliberately different machines.

Putting everything on one box is cheaper right up until one of its problems becomes all of them. The separations below are design decisions rather than the shape the hardware happened to take.

Mail runs on its own nodes

Different sending reputation, a different scaling curve and a different attack surface from a web node. Put mail on a web node and one of those three problems becomes all three.

Databases on dedicated nodes

A shared engine with your own database, your own user and your own grants — rather than a container each, which would hold the same engine in memory dozens of times over.

Websites in a container each

The website is the isolation unit, not the account. Five sites is five boundaries, so a compromise of one does not reach the other four.

Backups leave the machine

Written to object storage with per-tenant keys, because a backup that lives on the box it protects is not a backup. Kept fourteen days and restored by you from the panel.

Statistics go to their own store

Per-site CPU, memory, bandwidth and disk land in an analytics store every minute rather than in the panel's own database, which is what lets them go back ninety days without slowing anything down.

A location has to qualify

A location only offers a plan when a node there holds every role that plan needs and is under its capacity watermark. That is why you are not asked to pick one and then told it cannot be done.

Frequently asked questions

Can I choose which country my server is in?

Ask before you order. There is deliberately no region picker at checkout: a location only offers a plan when it can actually serve every part of it, so what is offered is what will work. If a particular country matters to you, for latency or for a legal reason, tell us first and we will tell you what is available.

Do I have to pick a region for DNS?

No, and you will not be asked to. DNS is served from all twelve points of presence rather than placed in one, so the question does not arise.

Is IPv6 available?

Where a location serves it, yes, and your machine gets it as a matter of course rather than after a support request. Whether yours does is a question worth asking before you order if you depend on it.

Where are backups kept?

Off the machine they protect, in object storage, encrypted with keys held per tenant. Daily, kept fourteen days, and replayed on a schedule so that they are known to work before you need one.

How fast will my site be from where my visitors are?

We will not put a number on that, because the honest one depends on your visitors, your application and the route between them, none of which we control. What we can tell you is where DNS answers from and what the machine you are buying is.

What happens if a point of presence goes offline?

Routing sends resolvers to another one. Because every nameserver answers for every zone, there is nothing to move and no delegation to change — which is the whole reason for running it this way.

The machine, rather than the network around it

Full KVM, root by key at first boot, snapshots daily and kept a fortnight, and resizing between 1 and 32 vCPU without a rebuild.

See cloud servers

Somewhere specific in mind?

If your answer to where this has to run is a country rather than a shrug, say so before you order and we will tell you plainly what is available and what is not.

Ask us