SoftwareSolve

Nexora

DNS platform

One console for DNS, from a single site to a national network. Change it without taking anything down.

A DNS platform for enterprises and telecom operators. Resolving and filtering, plus authoritative DNS, run from one console across a fleet of servers.

For enterprises and telecom operators

Nexora dashboard: AI insights summary, queries per second, cache hit ratio, engines connected and upstream health
Traffic, cache, blocking and upstream health across every resolver.
Why Nexora

DNS is critical, and changing it is risky

Every connection on your network starts with a DNS lookup. Push a bad change or overload a resolver and every user feels it at once. Many operators still run resolvers, filtering appliances and zone servers side by side, each with its own configuration. Changes go in one server at a time, and nobody sees what broke until customers start calling.

What makes it different

Why it’s built the way it is.

01

Rollouts that stop themselves

A configuration change lands on a canary server first. It only goes further if the canary’s error rate stays within limits; if not, the rollout halts and you can roll it back.

02

Answers even when management is down

Every DNS server keeps the last configuration it applied and serves from it if the console can’t be reached. No query ever waits on a database.

03

One engine, not a stack of boxes

Forwarding, full recursion, DNSSEC, filtering and per-client policy all run in the same engine. So do encrypted DNS and authoritative zones, and one console manages the lot.

04

The AI suggests. Your operators decide.

AI agents flag anomalies, forecast capacity and rate the risk of a rollout, by default on a model inside your own network. Nothing changes until an operator applies it. Every change goes in the audit log.

How it works

From setup to everyday use.

  1. 1

    Install the management plane

    Deploy the console and API with Helm, the Kubernetes operator or Docker Compose, on top of PostgreSQL. Add replicas as you need them.

  2. 2

    Enrol DNS engines into groups

    An engine joins with a one-time token and connects out over mutual TLS. It lands in an engine group: one per data centre, say, or one per customer.

  3. 3

    Configure once, in the console or the API

    Set upstreams, recursion, filtering, policy groups and zones, for the whole fleet or just one group.

  4. 4

    Roll out in stages

    Every change becomes a versioned snapshot. Canaries get it first; the rest of the group follows once health checks pass.

  5. 5

    Watch, investigate, improve

    Dashboards, the query log, Prometheus metrics and AI findings show what the network is doing. They also show what needs a look.

A closer look

See Nexora at work.

Query log with an anomaly banner, a plain-language question box, filters and per-query results
Every query, why it was answered or blocked, and questions in plain language.
Policy groups by client network with filter categories and safe search per group
Different filtering for each customer, segment or site, chosen by source address.
Canary rollout of a configuration change with an AI risk assessment and per-engine progress
Changes reach a canary first and only continue if health checks pass.
AI anomalies: an NXDOMAIN burst, possible DNS tunnelling and a SERVFAIL rise, each with clients and sample domains
AI flags anomalies; operators decide what to do.
Features

What it does, in detail.

Resolving

  • Forwarding and full recursion Forward over UDP, TCP, DoT or DoH. Or resolve iteratively, starting at the root servers.
  • DNSSEC validation Recursive and forwarded answers are both validated. Trust anchors update automatically, and negative trust anchors are supported.
  • Fast response cache A wire-format cache with serve-stale, so answers keep flowing while an upstream is slow.
  • Encrypted DNS for clients Listeners for DNS over TLS, HTTPS and QUIC, plus Oblivious DoH. The console pushes out the certificates.

Filtering and policy

  • Category filtering Switch on categories like malware, phishing, ads and tracking, or adult content. Maintained public blocklists feed them.
  • Per-client policy groups Each subscriber segment, site or customer gets its own lists, categories and safe search, picked by source address.
  • Response Policy Zones Load RPZ feeds from files or by zone transfer, TSIG included.
  • Rewrites and allowlists Answer chosen names with your own records. Keep trusted domains out of blocking.

Authoritative DNS

  • Primary and secondary zones Serve your own zones, with AXFR/IXFR transfers, NOTIFY and access controls.
  • Online DNSSEC signing Zones are signed with scheduled key rollovers. Keys sit under a key-encryption key or in a PKCS#11 HSM.
  • Dynamic updates and import RFC 2136 dynamic updates. BIND zone files import and export.

Operations and security

  • Fleet management Engine groups and join tokens, certificate rotation and revocation, and one view of fleet health.
  • Query log to your stack Keep query logs in Nexora or ship them to ClickHouse, OpenSearch or Loki. OpenTelemetry export is there too.
  • Access and audit Viewer, operator and admin roles. Single sign-on through OIDC, API tokens, and a full audit log.
  • Open API and MCP Anything you can do in the console you can do through the documented REST API. An MCP server lets AI assistants in as well.
Use cases

Who uses it, and for what.

Telecom operators

Run subscriber resolvers across several data centres. Sell family-safe DNS as a product using policy groups, and roll changes out one region at a time.

Enterprises

Swap the patchwork of resolvers and filtering appliances for one managed platform that stops malware and phishing at the DNS layer, at every site.

Managed service providers

Each customer gets its own engine group and policies. Your team runs all of them from one console.

At a glance

Runs on
Linux servers, virtual machines or Kubernetes
Deployment
On-premises or in your own cloud: Helm chart, Kubernetes operator or Docker Compose
Requirements
PostgreSQL for the management plane
Protocols
DNS over UDP/TCP, DoT, DoH, DoQ, Oblivious DoH; DNSSEC; AXFR/IXFR; RPZ
Integrates with
Prometheus, OpenTelemetry, ClickHouse, OpenSearch, Loki, OIDC single sign-on, PKCS#11 HSMs
Built with
Rust DNS engine, Go management plane, React console

Questions

Does our DNS data leave our network?

No. Nexora runs on your infrastructure. By default the AI features only talk to a model endpoint on a private address. Sending data to a public AI service is off until someone deliberately turns it on.

What if the management console goes down?

DNS carries on. Each engine serves from the last configuration it applied, then reconnects once the management plane is back.

Can the AI change our configuration?

No. The AI layer only suggests. A proposal takes effect when an operator has reviewed and approved it, and that change is audited like any other.

Can we start small?

Yes. Start on a single host with Docker Compose. Later, grow to many engine groups on Kubernetes, still managed from the same console.

How is it priced?

It depends on scope: how many engines, which features and what level of support. Book a demo and we’ll size it with you, then send a proposal.

Solve

AI that solves one job, properly.

See it on your own data.

We run the demo with your data, then propose a scope and pricing.

info@azrty.com+971 58 562 6444Meydan Grandstand, 6th floor, Dubai
Nexora: DNS for one server or a whole fleet, with AI insights your operators approve. | Azrty