Long-term DNS infrastructure
The authoritative DNS infrastructure consists of one hidden primary and three public secondary DNS servers. The hidden primary prepares and signs the zones with DNSSEC; the public secondary servers receive those zones and answer DNS queries.
The environment currently manages approximately 1,000 active DNS zones and historically handled more. Ongoing work covers Linux server administration, configuration changes, automation, monitoring and gradual modernisation. The specific signing migration from OpenDNSSEC to BIND covered more than 1,000 zones.