ManageEngine Cloud DNS, officially branded as ManageEngine CloudDNS, is a cloud-based authoritative DNS management service designed to keep business domains available, responsive, and easier to control from a centralized console. It combines DNS hosting with traffic steering, health monitoring, automated failover, DNSSEC, analytics, and administrative controls for organizations that do not want to maintain their own globally distributed authoritative DNS infrastructure.
CloudDNS is relevant to more than public websites. SaaS platforms, e-commerce applications, customer portals, APIs, distributed services, and multi-region workloads all depend on DNS being available before users can reach the application itself. ManageEngine uses globally distributed nameservers and routing controls to improve resolution reliability while giving administrators tools to decide which healthy endpoint should answer for a particular user or network.
For organizations evaluating a ManageEngine Cloud DNS license, the main sizing questions are the number of managed domains and records, how many administrators require access, and whether the environment needs DNS monitoring, automated failover, GeoDNS, filters, API access, or advanced auditing.
Quick Benefits
- Cloud-hosted authoritative DNS management
- Unlimited DNS queries across paid plans
- Globally distributed nameservers
- GeoDNS-based traffic steering
- IP subnet and ASN-based DNS filtering
- DNS failover with endpoint health monitoring
- Weighted and priority-based traffic distribution
- DNSSEC support
- DNS query analytics
- Primary and Secondary DNS support

ManageEngine Cloud DNS At a Glance
Official product name: ManageEngine CloudDNS
Parent Category: ManageEngine License
Primary role: Authoritative cloud DNS management
Deployment: SaaS / cloud-hosted
DNS traffic: Unlimited queries on current paid plans
Traffic management: GeoDNS, IP subnet, ASN, weighted and priority routing
Availability: Health monitoring and automatic DNS failover
DNS security: DNSSEC, redundancy, TSIG-supported transfers and access controls
License Overview
A ManageEngine Cloud DNS license is subscription-based and should be selected according to how much DNS infrastructure the organization needs to manage rather than the number of DNS lookups generated by users.
That is an important distinction. ManageEngine currently provides unlimited queries across the four main paid CloudDNS plans. Capacity instead increases through domain count, DNS-record count, user access, monitors, traffic filters and Global Traffic Directed domains. This can make cost planning more predictable for websites or SaaS applications whose DNS query volume changes significantly during campaigns, traffic spikes or seasonal events.
The entry Basic plan is intended for relatively simple authoritative DNS requirements. Standard and Premium progressively add more domains, monitoring, traffic-direction capabilities and administrative users. Enterprise increases those limits further and includes capabilities such as API access, audit functions and zone versioning as part of the plan.
ManageEngine also allows organizations to extend several capacities through add-ons, so moving to another plan is not always necessary simply because one resource—such as domains or monitors—has reached its base allocation.
Product Overview
Authoritative DNS Management
CloudDNS hosts authoritative DNS zones and responds to requests for the organization’s domains using ManageEngine’s distributed DNS infrastructure.
Administrators can centrally maintain records and zones rather than operating multiple authoritative DNS servers themselves. This is useful for organizations whose applications span different hosting providers, data centers or clouds but still need one place to manage external DNS.
CloudDNS supports several domain types. Primary GeoDNS is intended for environments that need advanced traffic management, monitoring, DNSSEC and failover. Primary AXFR allows the CloudDNS zone to act as a primary source for secondary DNS systems through zone transfers. A Secondary zone can instead receive DNS information from an external primary server using AXFR.
The correct type should be chosen before building the DNS architecture because the available traffic-management functions differ between them.
GeoDNS and Traffic Steering
Not every DNS query needs to receive the same answer.
An application with servers in Europe, Asia and North America may want users to reach an endpoint closer to their geographic location. CloudDNS provides GeoDNS capabilities for this type of routing and can also apply policies using IP subnet and Autonomous System Number information.
This makes DNS part of application delivery. Instead of resolving every user toward a single IP address, DNS responses can guide users toward an appropriate data center, cloud region, CDN endpoint or service instance according to the organization’s routing policy.
DNS Failover and Availability
CloudDNS can actively monitor the services behind DNS records. If a primary server becomes unavailable, DNS traffic can be redirected toward a configured backup rather than continuing to return an address for a failed resource. ManageEngine currently supports failover for records such as A, AAAA, ALIAS and CNAME. Traffic can also be distributed using weighted or priority-based methods. Weighted configurations divide queries between healthy endpoints according to assigned values, while priority-based failover prefers one endpoint and moves to the next when the preferred resource fails. This is particularly useful when an organization operates the same service from multiple data centers or cloud regions.
DNS Security and Control
DNS availability is only part of the requirement; the answers also need to be trustworthy. CloudDNS supports DNSSEC, allowing DNS responses to be cryptographically validated and helping protect against attacks that attempt to return forged DNS information. DNSSEC is available on current paid plans, and CloudDNS can create the DNSKEY and DS information needed to complete validation through the domain registrar. The broader CloudDNS security model also includes redundant nameservers, role-based administration, auditing options, TSIG-secured zone-transfer scenarios and DDoS-resilient DNS infrastructure.
How ManageEngine Cloud DNS Works
After a domain is created in CloudDNS, administrators configure the required DNS zone and resource records. The registrar is then updated so the domain delegates authoritative DNS resolution to the appropriate ManageEngine nameservers. For straightforward environments, CloudDNS simply answers queries according to the configured records. More advanced deployments can introduce GeoDNS, network-based filters or Global Traffic Directed domains so responses change according to user location or other routing conditions.
Where high availability is required, CloudDNS monitors the endpoints associated with selected records. When the primary resource becomes unhealthy, the DNS response can be adjusted toward a configured healthy resource. The result is that DNS becomes an active component of application availability rather than a static table of hostnames and IP addresses.

Core Technical Flow
User / Application DNS Query
→ ManageEngine CloudDNS Authoritative Nameserver
→ DNS Zone and Record Evaluation
→ GeoDNS / IP / ASN / Traffic Filter Evaluation
→ Endpoint Health and Failover Check
→ DNSSEC-Signed Response where enabled
→ Selected Application / Data Center / Cloud Endpoint
→ DNS Analytics and Monitoring
Not every request needs all of these stages. A simple authoritative zone may return a normal DNS record without traffic-direction or failover logic.
Options and Licensing Models
| Plan | Domains | DNS Records | Users | Monitors | Global Traffic Directed Domains | Filters | Key Position |
|---|---|---|---|---|---|---|---|
| Basic | 5 | 5,000 | 1 | — | — | — | Basic authoritative DNS, DNSSEC and analytics |
| Standard | 50 | 50,000 | 3 | 2 | 1 | 2 | Small-to-mid-size environments needing monitoring and traffic steering |
| Premium | 100 | 100,000 | 5 | 10 | 5 | 10 | Larger application environments with greater failover and routing requirements |
| Enterprise | 200 | 200,000 | 8 | 20 | 10 | 20 | Larger DNS estates requiring API, audit and zone-versioning capabilities |
All four current paid plans include unlimited DNS queries, DNSSEC, analytics and vanity nameservers. ManageEngine also offers add-on capacity for domains, records, monitors, filters and users. API, audit and zone versioning are included in Enterprise and can currently be purchased as add-ons for lower paid plans.
The right plan is therefore not always the one with the highest domain limit. An organization managing only twenty domains but requiring numerous health monitors and advanced routing policies may have different licensing needs from a company hosting one hundred simple static zones.
Features and Benefits
One useful feature of CloudDNS is that DNS management and availability monitoring operate together. In a conventional DNS environment, another monitoring product may detect that an application server is down while DNS continues directing users toward it. CloudDNS can connect those two functions and modify routing when monitored resources fail.
Global traffic management can also improve the user experience for applications hosted in more than one region. Directing users toward geographically or topologically appropriate endpoints can reduce unnecessary latency while giving network teams control over where application traffic is sent.
CloudDNS analytics adds another layer of visibility. DNS query information can reveal traffic distribution, request patterns and how users are reaching different services. For application owners, this can be useful when reviewing geographic demand or investigating unexpected DNS behavior.
Zone versioning is valuable in operational environments where DNS changes need to be controlled carefully. Incorrect DNS modifications can make an otherwise healthy service unreachable, so maintaining previous zone states provides a practical rollback mechanism.
Compatibility and Requirements
Before moving a domain to CloudDNS, administrators should inventory the existing zone carefully. A missing MX, TXT, DKIM, SPF, DMARC or verification record can interrupt email or external services even when the main website continues working. The current DNS provider and zone-transfer method should also be identified. ManageEngine supports migration from providers including AWS Route 53, Google Cloud DNS, Microsoft Azure DNS and Cloudflare, while standard zone information can also be imported using supported formats.
Organizations using Secondary DNS should verify AXFR connectivity and TSIG requirements. If GeoDNS or failover will be introduced, determine the application endpoints, health-check method and desired routing behavior before changing production nameservers. DNSSEC requires coordination with the domain registrar because the DS information generated by CloudDNS must be published correctly in the parent zone. Enabling DNSSEC without completing that chain of trust correctly can make a domain unreachable to validating DNS resolvers.
How Activation and Deployment Work
CloudDNS is delivered as a cloud service, so there is no DNS server software or appliance to install. Deployment normally starts by creating the organization account and adding the required domain. Administrators then choose the appropriate zone type, import or recreate the existing DNS records and validate them against the current authoritative zone.
The next step is delegation. Nameserver records at the registrar are changed so authoritative queries begin reaching CloudDNS. For a production domain, this should be planned carefully around DNS TTL values to reduce propagation uncertainty during migration. Advanced capabilities can then be introduced gradually. DNSSEC can be enabled after the base zone is confirmed, health monitors can be attached to critical records, and GeoDNS or traffic filters can be added once normal resolution is stable. That staged approach is safer than changing DNS provider, enabling DNSSEC and introducing traffic steering at the same time.
Pricing and Quote Process
Pricing for a ManageEngine Cloud DNS license depends mainly on DNS estate size and the advanced routing functions the organization intends to use. The most useful information for a quote is the number of domains, DNS records, administrative users, monitors, filters and Global Traffic Directed domains. These are also the primary fields ManageEngine requests through its current CloudDNS quote form.
For an existing environment, also identify the current DNS provider, whether Secondary DNS or AXFR is required, whether DNSSEC is already enabled, and how many applications need automated failover. Organizations close to a plan limit should compare the cost of individual add-ons with the next subscription tier rather than automatically upgrading. A business that only needs several additional domains may be better served by domain add-ons, whereas an environment simultaneously adding administrators, monitors, filters and GTD zones may obtain more value from the higher plan.
ManageEngine pricing depends on your license edition, users, devices, deployment model, term, and support needs.
