Authoritative DNS · Anycast · Built for senders

Your domains.
Your nameservers.
Nobody else on them.

Private NS servers for cold email with Anycast IPs. Boot unlimited dedicated nameservers in one click. Stop sharing DNS with 40 million strangers on Cloudflare.

No credit card · First server free · Vanity NS on your own domain
firedns — zsh
$ firedns boot --name ns-eu-1 --brand mydomain.com
▸ allocating anycast IP ............ 203.0.113.42 
▸ provisioning PowerDNS instance ... 
▸ signing glue records ............. 
▸ ns1.mydomain.com  → LIVE
▸ ns2.mydomain.com  → LIVE
 nameserver online in 41s
Why not just use Cloudflare

Public DNS was built
for websites. Not senders.

01

Shared NS = shared reputation.

Public nameservers host millions of zones. One spammer on the same NS and blacklists start flagging the pool. Your domains inherit the damage.

02

Fingerprintable.

ns1.cloudflare.com on every cold email domain is a pattern. Filters learn patterns.

03

Zero sender tooling.

No bulk ops across 500 zones. No daily blacklist checks. No health alerts. You find out when replies stop.

Public service announcement

F**K SURBL.

Three steps so SURBL can't trace sh*t.

1

Use generic domains

No brand keywords. No shared registrant. Boring names nobody can cluster back to you.

That's your part
2

Boot unique private nameservers

Every domain resolves from a nameserver you own, on an IP nobody else shares. No pool. No pattern.

That's on us
3

Mask the footprint

Vanity NS, masked relationships, daily blacklist checks — and an alert before a listing ever hits a reply rate.

Also on us
🖕

Let's show SURBL a middle finger. Together.

Boot a Nameserver →
What you get

Infrastructure that acts like it's yours.
Because it is.

Feature 01

Unlimited dedicated nameservers

Boot as many as you want. Each one is its own PowerDNS instance on its own Anycast IP. One click. Live in under a minute.

+ BOOT SERVER
Feature 02

Anycast IPs, every server

Your NS answers from the nearest edge worldwide. Lower latency, DDoS absorption, no single point of failure.

Feature 03

Vanity NS on your domain

ns1.yourbrand.com, not ours. Glue records signed automatically. Nothing points back to FireDNS.

Feature 04

Weighted zone distribution

Set a weight per server. New zones auto-distribute by ratio. Isolate risky domains on their own NS.

ns-eu-1 · 50%   ns-us-1 · 30%   ns-quarantine · 20%
Feature 05

One API. Every zone. Every server.

Robust omnichannel REST API + CLI + MCP server. Create, read, update, delete records across all zones with one key.

$ curl -X POST https://api.firedns.io/v1/zones/*/records \
  -H "Authorization: Bearer $FIREDNS_KEY" \
  -d '{"type":"TXT","name":"_dmarc","content":"v=DMARC1; p=quarantine"}'
→ 412 zones updated · propagated in 3.1s
Feature 06

One-click bulk actions

Change DKIM on 400 domains. Rotate MX everywhere. Add a TXT to every zone. One action, one confirmation, done.

Feature 07

Daily spam-listing health check

Every zone, every NS IP, checked against 60+ blacklists daily.

acme-outreach.com
get-acme.co
acmehq.io
try-acme.net · listed on SORBS
Feature 08

Domain health notifications

Slack, email, webhook. Blacklist hit, NS unreachable, DKIM broken, SPF over 10 lookups — you know before your prospects do.

Feature 09

Domain masking

Hide registrant, hosting and NS relationships between sending domains. No shared footprint to reverse-engineer.

Feature 10

Auto DKIM / SPF / DMARC

Add a domain, get correct records generated. Pairs natively with icemail.ai mailbox provisioning.

Feature 11

Zone import

Paste a BIND file, connect Cloudflare, or import from ClouDNS. Migrate 1,000 zones in an afternoon.

Feature 12

Instant propagation

Record changes go live across all Anycast nodes in seconds, not TTL cycles.

Sixty seconds

Boot. Brand. Load. Send.

1

Boot

Click. Pick a region. Name your NS.

2

Brand

Point ns1/ns2.yourdomain.com at your new IPs. We sign the glue.

3

Load

Import zones or create them via API. Weighted distribution spreads them out.

4

Send

Daily health checks and alerts run in the background. You focus on replies.

Side by side

FireDNS vs the incumbents

FireDNSCloudflareClouDNS
Dedicated nameservers per customerPaid add-on
Vanity NS on your domainEnterprise only
Anycast IPs
Weighted zone distribution
Bulk record actions across all zonesLimited
Daily blacklist check per zone
Domain health alerts
Domain masking
MCP server for AI agents
Built for cold email
<0ms
avg query latency
0+
blacklists checked daily
0s
average boot time
0%
zones on dedicated NS
Pricing

Pay per server.
Zones are free.

Starter

$0/mo
  • 1 dedicated nameserver
  • Anycast IP
  • Unlimited zones
  • Daily health checks
  • API access
Boot for free
MOST POPULAR

Operator

$29/server/mo
  • Everything in Starter
  • Vanity NS branding
  • Weighted distribution
  • Bulk actions
  • Slack / webhook alerts
  • Domain masking
Start with Operator

Fleet

Custom
  • 10+ servers
  • Dedicated IP blocks
  • Priority propagation
  • SLA
  • White-label
Talk to us
Volume pricing from 5 servers · No per-zone fees · No per-query fees. Ever.
Questions

FAQ

Do I really get my own nameservers, or is it shared?

Your own. Each server is a dedicated PowerDNS instance on its own Anycast IP, serving only your zones. Nobody else's domains ever resolve from it.

What is Anycast and why does it matter for cold email?

The same IP is announced from multiple edge locations, so queries hit the nearest node. Faster lookups for receiving mail servers, and a DDoS on one region doesn't take your NS down.

Can I migrate from Cloudflare or ClouDNS?

Yes. Connect via API token or upload BIND zone files. We import records, generate the new NS set, and you flip nameservers at the registrar when ready.

Does FireDNS show up anywhere in my DNS?

No. With vanity NS your zones point to ns1.yourbrand.com. Glue records, SOA and NS records all carry your domain.

How does weighted distribution work?

Give each server a weight. New zones are assigned by ratio — e.g. 50/30/20. Set a server to 0 to quarantine it, or 100 to force new zones onto it.

Does it work with icemail.ai, OutreachFox, Smartlead, Instantly?

Yes. FireDNS is provider-agnostic authoritative DNS. icemail.ai provisioning writes DKIM/SPF/DMARC directly into your FireDNS zones.

Boot your first nameserver.
It's free.

60 seconds · No card · Vanity NS on your domain

Boot a Nameserver →