[ { "title": "Quick Start", "url": "https://borondns.com/docs/quick-start/", "description": "Install, configure, and verify your first secondary zone.", "category": "docs", "content": "BoronDNS is a secondary authoritative DNS server for Linux. It transfers zones from a primary using AXFR or IXFR and answers queries over UDP and TCP. The primary remains responsible for zone changes and DNSSEC signing.\nBefore you start\nInstall a verified release using the instal…" } ,{ "title": "Installation", "url": "https://borondns.com/docs/installation/", "description": "Choose a release artifact, verify it, and prepare the service.", "category": "docs", "content": "Choose an installation format\nGet artifacts from BoronDNS releases or the website's downloads page. Check the chosen tag's asset list for availability.\nFormatIntended use\nLinux x86_64 MUSL installer archiveStatic binaries and an installer for a native service.\nDebian/Ubuntu amd64…" } ,{ "title": "Configuration", "url": "https://borondns.com/docs/configuration/", "description": "Configure listeners, zone transfers, credentials, and persistent state.", "category": "docs", "content": "Generate a complete starting configuration with borondns --example-config. The default service path is /etc/borondns-secondary/config.toml.\nListeners and a zone\nThis small example uses local high ports and an unsigned transfer. Use it only on a trusted private test network. Repla…" } ,{ "title": "Configuration Reference", "url": "https://borondns.com/docs/config-reference/", "description": "Find the full configuration schema, examples, and override rules.", "category": "docs", "content": "The repository maintains the detailed settings alongside the implementation:\n\nConfiguration guide: settings, precedence, environment overrides, credentials, and tuning.\nCommented example TOML: the complete example to adapt.\nCatalog zones: discovery and member transfer policies.\n\n…" } ,{ "title": "BoronDNS CLI", "url": "https://borondns.com/docs/cli-reference/", "description": "Generate, validate, inspect, and run a BoronDNS configuration.", "category": "docs", "content": "Use the borondns executable to prepare configuration and run the server. Consult your installed binary's --help for its complete command surface.\nCommon commands\nborondns --help\nborondns --version\nborondns --example-config\nborondns --validate-config /etc/borondns-secondary/config…" } ,{ "title": "TSIG Setup", "url": "https://borondns.com/docs/tsig/", "description": "Authenticate primary-to-secondary transfers with a shared key.", "category": "docs", "content": "TSIG authenticates transfer messages using a shared secret. Configure the same key name, algorithm, and secret on the primary and BoronDNS. Generate the secret once and distribute it securely to both sides.\nCreate a secret\nFor an HMAC-SHA256 key:\nopenssl rand -base64 32\nStore the…" } ,{ "title": "Monitoring", "url": "https://borondns.com/docs/monitoring/", "description": "Check readiness, zone freshness, transfer failures, and DNS answers.", "category": "docs", "content": "Enable a private management listener\n[health]\nbind_address = "127.0.0.1"\nbind_port = 8080\nThese endpoints use plain HTTP and have no authentication. Keep them on loopback or a private management network.\nHealth probes\nEndpointMeaning\n/livezThe process can respond, inclu…" } ,{ "title": "Security Hardening", "url": "https://borondns.com/docs/security/", "description": "Protect transfers, management access, credentials, and service state.", "category": "docs", "content": "Protect transfers and management\nRequire TSIG for static zones with transfer.require_tsig = true, restrict NOTIFY sources, and use XoT where transfer encryption is needed. XoT protects outbound transfers only; it does not create an encrypted client-query listener.\nKeep management…" } ,{ "title": "Architecture", "url": "https://borondns.com/docs/architecture/", "description": "How BoronDNS transfers, persists, and publishes secondary zones.", "category": "docs", "content": "BoronDNS separates zone acquisition from query serving. It obtains data from configured primaries, validates transfers, and publishes complete generations for UDP and TCP query workers.\nFrom primary to answer\n\nStatic configuration or catalog membership establishes transfer plans.…" } ,{ "title": "Protocol Support", "url": "https://borondns.com/docs/rfcs/", "description": "Understand supported DNS features and find scoped RFC evidence.", "category": "docs", "content": "BoronDNS provides secondary authoritative DNS. Its feature reference describes implemented behavior and limits; the RFC compliance register records scoped claims and evidence.\nMain capabilities\nCapabilityScope\nUDP and TCP DNSAuthoritative answers, EDNS handling, and TCP retry aft…" } ,{ "title": "BoronGun", "url": "https://borondns.com/docs/borongun/", "description": "Run a DNS response check and find the full load-testing guide.", "category": "docs", "content": "BoronGun is a separate UDP DNS traffic generator for response checks, RRL tests, and throughput measurements. Release installer archives include the boron-gun binary.\nCheck a response\nAgainst a server you operate, replace the documentation address and query name:\nboron-gun --prob…" } ,{ "title": "Documentation", "url": "https://borondns.com/docs/", "description": "Essential guides for installing, configuring, and operating BoronDNS. Find complete references and advanced topics in the project repository.", "category": "docs", "content": "" } ,{ "title": "BoronDNS achieved 26 Mqps on a single 20-core ARM computer", "url": "https://borondns.com/news/gx10-af-xdp-benchmark/", "description": "BoronDNS delivered 26.007 million positive DNS responses per second on an ASUS Ascent GX10, with 0.00061–0.00142% loss across three fresh 30-second runs.", "category": "news", "content": "BoronDNS achieved 26.007 million positive DNS responses per second on a single ASUS Ascent GX10, using its NVIDIA GB10 processor and ConnectX-7 network adapter.\nThe test used BoronDNS's opt-in AF_XDP zero-copy path with CPU-local queue workers. Across three fresh 30-second runs, …" } ,{ "title": "BoronGun 0.9 preview: scriptable attack profiles", "url": "https://borondns.com/news/borongun-preview/", "description": "Custom query mixes, weighted record types, and a Lua-scriptable profile format land in the next BoronGun release.", "category": "news", "content": "BoronGun exists so you find your DNS server's breaking point before an attacker does. 0.9 makes the load profiles themselves a lot more expressive.\nWhat's landing\n\nWeighted query mixes — define what fraction of traffic is A, AAAA, ANY, or garbage qtypes, instead of a flat round-r…" } ,{ "title": "BoronDNS 1.0.0-beta.1 released", "url": "https://borondns.com/news/beta-1/", "description": "First public beta. AXFR, IXFR, XoT, RFC 9018 cookies, and RRL out of the box.", "category": "news", "content": "We're happy to announce the first public beta of BoronDNS.\nWhat's in beta.1\n\nZone transfers — AXFR and IXFR, with incremental diff tracking\nZone Transfer over TLS (XoT, RFC 9103) — encrypted transfers end-to-end\nDNS cookies (RFC 9018) — stateless client verification\nResponse Rate…" } ,{ "title": "Hardening advisory: tighten default RRL thresholds before you expose port 53", "url": "https://borondns.com/news/rrl-hardening-advisory/", "description": "The out-of-the-box Response Rate Limiting defaults are tuned for compatibility, not for hostile networks. Here's what to change before going to production.", "category": "news", "content": "This is a hardening advisory, not a vulnerability disclosure — but it's important enough that we're putting it in the news feed rather than burying it in the docs.\nThe issue\nBoronDNS ships with conservative RRL (Response Rate Limiting) defaults so that legitimate high-volume reso…" } ,{ "title": "Why we built a secondary-only DNS server", "url": "https://borondns.com/news/secondary-only-philosophy/", "description": "Authoritative-only, secondary-only: the design constraint that shaped every line of BoronDNS.", "category": "news", "content": "Most authoritative DNS servers try to do everything: primary and secondary, dynamic updates, DNSSEC signing, sometimes even recursive resolution bolted on as an afterthought. BoronDNS does one thing.\nThe constraint\nBoronDNS only ever serves zones it received via AXFR/IXFR from an…" } ,{ "title": "News", "url": "https://borondns.com/news/", "description": "Releases, security advisories, and updates from the BoronDNS team.", "category": "news", "content": "" } ,{ "title": "Downloads", "url": "https://borondns.com/downloads/", "description": "Release binaries, packages, and source archives for BoronDNS. Signed and checksummed.", "category": "releases", "content": "" } ,{ "title": "BoronDNS — Secondary-Only DNS by INTEGRITY Ltd.", "url": "https://borondns.com/", "description": "A memory-safe, secondary-only authoritative DNS server. Purpose-built for the public secondary tier of modern DNS. — Pre-release software, not intended for production use.", "category": "pages", "content": "" } ,{ "title": "BoronDNS", "url": "https://borondns.com/borondns/", "description": "The secondary-only authoritative DNS server. Memory-safe Rust, lock-free reads, hardened against floods, reflection and slowloris by design.", "category": "pages", "content": "" } ,{ "title": "BoronGun", "url": "https://borondns.com/borongun/", "description": "Generate high-rate DNS load against your own infrastructure to verify capacity before attackers do.", "category": "pages", "content": "" } ,{ "title": "Services", "url": "https://borondns.com/services/", "description": "Managed secondary DNS by Integrity Ltd. — geographically separate nameservers for your zones, monitored around the clock.", "category": "pages", "content": "" } ,{ "title": "The BoronDNS Suite", "url": "https://borondns.com/solutions/", "description": "BoronDNS · BoronGun · Services — three tools, one purpose: reliable secondary DNS.", "category": "pages", "content": "" } ,{ "title": "Support", "url": "https://borondns.com/support/", "description": "Community support via GitHub and IRC. Commercial SLA options available from Integrity Ltd.", "category": "pages", "content": "" } ]