Nexora
DNS platformOne console for DNS, from a single site to a national network. Change it without taking anything down.
A DNS platform for enterprises and telecom operators. Resolving and filtering, plus authoritative DNS, run from one console across a fleet of servers.
For enterprises and telecom operators

DNS is critical, and changing it is risky
Every connection on your network starts with a DNS lookup. Push a bad change or overload a resolver and every user feels it at once. Many operators still run resolvers, filtering appliances and zone servers side by side, each with its own configuration. Changes go in one server at a time, and nobody sees what broke until customers start calling.
Why it’s built the way it is.
Rollouts that stop themselves
A configuration change lands on a canary server first. It only goes further if the canary’s error rate stays within limits; if not, the rollout halts and you can roll it back.
Answers even when management is down
Every DNS server keeps the last configuration it applied and serves from it if the console can’t be reached. No query ever waits on a database.
One engine, not a stack of boxes
Forwarding, full recursion, DNSSEC, filtering and per-client policy all run in the same engine. So do encrypted DNS and authoritative zones, and one console manages the lot.
The AI suggests. Your operators decide.
AI agents flag anomalies, forecast capacity and rate the risk of a rollout, by default on a model inside your own network. Nothing changes until an operator applies it. Every change goes in the audit log.
From setup to everyday use.
- 1
Install the management plane
Deploy the console and API with Helm, the Kubernetes operator or Docker Compose, on top of PostgreSQL. Add replicas as you need them.
- 2
Enrol DNS engines into groups
An engine joins with a one-time token and connects out over mutual TLS. It lands in an engine group: one per data centre, say, or one per customer.
- 3
Configure once, in the console or the API
Set upstreams, recursion, filtering, policy groups and zones, for the whole fleet or just one group.
- 4
Roll out in stages
Every change becomes a versioned snapshot. Canaries get it first; the rest of the group follows once health checks pass.
- 5
Watch, investigate, improve
Dashboards, the query log, Prometheus metrics and AI findings show what the network is doing. They also show what needs a look.
See Nexora at work.




What it does, in detail.
Resolving
- Forwarding and full recursion Forward over UDP, TCP, DoT or DoH. Or resolve iteratively, starting at the root servers.
- DNSSEC validation Recursive and forwarded answers are both validated. Trust anchors update automatically, and negative trust anchors are supported.
- Fast response cache A wire-format cache with serve-stale, so answers keep flowing while an upstream is slow.
- Encrypted DNS for clients Listeners for DNS over TLS, HTTPS and QUIC, plus Oblivious DoH. The console pushes out the certificates.
Filtering and policy
- Category filtering Switch on categories like malware, phishing, ads and tracking, or adult content. Maintained public blocklists feed them.
- Per-client policy groups Each subscriber segment, site or customer gets its own lists, categories and safe search, picked by source address.
- Response Policy Zones Load RPZ feeds from files or by zone transfer, TSIG included.
- Rewrites and allowlists Answer chosen names with your own records. Keep trusted domains out of blocking.
Authoritative DNS
- Primary and secondary zones Serve your own zones, with AXFR/IXFR transfers, NOTIFY and access controls.
- Online DNSSEC signing Zones are signed with scheduled key rollovers. Keys sit under a key-encryption key or in a PKCS#11 HSM.
- Dynamic updates and import RFC 2136 dynamic updates. BIND zone files import and export.
Operations and security
- Fleet management Engine groups and join tokens, certificate rotation and revocation, and one view of fleet health.
- Query log to your stack Keep query logs in Nexora or ship them to ClickHouse, OpenSearch or Loki. OpenTelemetry export is there too.
- Access and audit Viewer, operator and admin roles. Single sign-on through OIDC, API tokens, and a full audit log.
- Open API and MCP Anything you can do in the console you can do through the documented REST API. An MCP server lets AI assistants in as well.
Who uses it, and for what.
Telecom operators
Run subscriber resolvers across several data centres. Sell family-safe DNS as a product using policy groups, and roll changes out one region at a time.
Enterprises
Swap the patchwork of resolvers and filtering appliances for one managed platform that stops malware and phishing at the DNS layer, at every site.
Managed service providers
Each customer gets its own engine group and policies. Your team runs all of them from one console.
At a glance
- Runs on
- Linux servers, virtual machines or Kubernetes
- Deployment
- On-premises or in your own cloud: Helm chart, Kubernetes operator or Docker Compose
- Requirements
- PostgreSQL for the management plane
- Protocols
- DNS over UDP/TCP, DoT, DoH, DoQ, Oblivious DoH; DNSSEC; AXFR/IXFR; RPZ
- Integrates with
- Prometheus, OpenTelemetry, ClickHouse, OpenSearch, Loki, OIDC single sign-on, PKCS#11 HSMs
- Built with
- Rust DNS engine, Go management plane, React console
Questions
Does our DNS data leave our network?
No. Nexora runs on your infrastructure. By default the AI features only talk to a model endpoint on a private address. Sending data to a public AI service is off until someone deliberately turns it on.
What if the management console goes down?
DNS carries on. Each engine serves from the last configuration it applied, then reconnects once the management plane is back.
Can the AI change our configuration?
No. The AI layer only suggests. A proposal takes effect when an operator has reviewed and approved it, and that change is audited like any other.
Can we start small?
Yes. Start on a single host with Docker Compose. Later, grow to many engine groups on Kubernetes, still managed from the same console.
How is it priced?
It depends on scope: how many engines, which features and what level of support. Book a demo and we’ll size it with you, then send a proposal.
AI that solves one job, properly.
NovaGrade
Schools and exam boardsAI marking of open-ended exam answers, criterion by criterion. It is built into Kodak scanning, so teachers review instead of mark.
Learn moreEnterprise AI prompt libraryPromptForge
EnterprisesA shared library for AI prompts. Teams keep the prompts that work, version them and pass them on, so nobody starts from scratch.
Learn moreSee it on your own data.
We run the demo with your data, then propose a scope and pricing.