Use cases
This document highlights common scenarios for managing and optimizing domain and network infrastructure using DigiCert® DNS. These include:
Each use case outlines the business need it addresses, links to core features, and summarizes organizational benefits, providing a practical reference for applying DigiCert® DNS in real-world environments.
Overview
This use case supports the creation, customization, and governance of nameserver defaults to align with architectural and compliance standards.
Core capabilities
Business need
Managing DNS configurations at scale requires the consistent assignment of infrastructure components across domains. DigiCert® DNS enables the dynamic and centralized configuration of nameservers and nameserver sets by eliminating inefficiencies, reducing misconfiguration risk, and improving security consistency across domains. DNS teams can define and manage reusable, governed nameserver structures to support automation, compliance, and operational scale.
Business benefit
Enforce configuration consistency: Ensure all domains follow standardized DNS infrastructure by applying reusable nameserver sets.
Improve operational efficiency: Reduce misconfiguration risk and administrative overhead through automation and centralized management.
Reduce setup time: Accelerate domain provisioning by eliminating repetitive, manual nameserver assignments.
Streamline infrastructure changes: Simplify updates by modifying nameserver sets once and propagating changes to all linked domains.
Support governance and compliance: Meet architectural or regulatory standards by designating and enforcing system-wide default nameserver sets.
Overview
This use case focuses on implementing DNS security controls that protect infrastructure and data while meeting regulatory and internal compliance requirements.
Core capabilities
Business need
DNS is a high-value attack vector. Misconfigured or unprotected DNS services can lead to data breaches, domain hijacking, DDoS amplification, cache poisoning, and regulatory penalties. Many compliance frameworks also require that DNS activity be securely logged, monitored, and protected against unauthorized access. DigiCert® DNS’s robust access controls - including API key management, token-based authentication, and TSIG enforcement - help organizations prevent credential misuse, configuration drift, and unauthorized changes, while maintaining visibility and alignment with security and compliance standards.
Business benefit
Block unauthorized changes: Prevent unauthorized access and configuration drift across your DNS environment through credential-based access controls.
Catch threats in real time: Detect and respond to suspicious activity before it impacts users or systems.
Defend against critical DNS threats: Protect against data breaches, domain hijacking, DDoS amplification, cache poisoning, and regulatory penalties.
Protect users from DNS-based attacks: Safeguard users from malicious or spoofed DNS responses to maintain trust and integrity.
Stay compliant and in control: Log, monitor, and secure DNS activity to meet internal policies and external audit requirements.
Overview
This use case covers the full domain lifecycle - from registration and configuration to ongoing maintenance - with support for primary and secondary settings, redundancy, customization, and visibility.
Core capabilities
Business need
A properly configured domain is crucial for ensuring that services are accessible over the internet. Mistakes in setup or delegation can lead to broken applications, lost web traffic and revenue, user dissatisfaction, and increased vulnerability to spoofing or hijacking. As organizations grow, managing domain configurations manually can become error-prone and inefficient. Organizations can ensure availability, consistency, and operational transparency by automating and centralizing domain configurations through DigiCert® DNS. This approach also helps proactively identify risks and reduce troubleshooting time.
Business benefit
Build user trust with secure, resilient domains: Safeguard your brand and users from threats with enterprise-grade DNS security and proactive monitoring.
Deliver uninterrupted experiences for your users: Prevent downtime with redundant configurations and seamless domain failover capabilities.
Keep your services reachable and reliable: Ensure your users can access your digital services without disruption through robust, automated domain management.
Scale confidently with streamlined domain operations: Automate routine tasks and manage complex environments efficiently.
Simplify compliance while strengthening control: Gain complete visibility and control over domain changes with built-in auditing, role-based access, and policy enforcement.
Overview
This use case focuses on managing DNS services in multi-tenant environments, where domains, records, users, roles, groups, and permissions coexist on a shared platform.
Core capabilities
Business need
Effective multi-tenancy ensures isolation, security, and operational efficiency. As organizations scale, managed DNS solutions that maintain strict tenant separation become critical—without them, there is a risk of unauthorized access, increased operational overhead, and compliance issues. DigiCert® DNS simplifies multi-tenant management by enabling seamless onboarding, granular tenant control, and centralized operations, all without compromising security or governance.
Business benefit
Keep tenant data secure: Maintain strict separation of tenant data with granular control and isolation.
Onboard users without friction: Enable seamless and secure user onboarding across tenant environments.
Prevent cross-tenant access: Protect against unauthorized access between tenants to ensure security and trust.
Simplify management at scale: Decrease operational overhead and centralize administration across tenants.
Stay ahead of compliance risks: Avoid potential violations by enforcing strong access and data boundaries.
Overview
This use case involves creating, updating, retrieving, and deleting DNS records that define how domain names map to network services. It spans primary and secondary domains to ensure records remain accurate and consistent across the infrastructure.
Core capabilities
Business need
DNS record accuracy is critical to service reliability, as incorrect or outdated records can disrupt core functions such as web hosting, email delivery, and security validation. As environments become more dynamic - with microservices, automated infrastructure, and cloud platforms - DigiCert® DNS helps organizations reduce risk and increase operational agility by supporting agile deployments, smooth service migrations and rollbacks, and robust security and compliance efforts, while offering deep visibility into DNS configurations.
Business benefit
Adapt to modern infrastructure: Support dynamic environments to stay ahead of the curve.
Deploy and roll back with ease: Support agile deployments, service migrations, and rollbacks without disruption.
Keep essential services running: Avoid disruptions to web hosting, email delivery, and security validation.
Move faster with confidence: Increase operational agility to respond quickly to change.
Prevent costly DNS errors: Protect against incorrect or outdated records that can disrupt critical services.
Strengthen security and compliance: Leverage robust capabilities to meet regulatory and internal standards.
Understand your DNS inside and out: Gain deep visibility into DNS configurations to improve control and decision-making.
Overview
This use case enforces fine-grained access control in DNS management by assigning roles and permissions to users or groups. Role-based access control (RBAC) lets administrators tailor access by job function, responsibility, or organizational structure.
Core capabilities
Business need
As DNS environments scale in complexity, controlling who can make critical changes becomes essential. RBAC enforces the principle of least privilege (PoLP), minimizing the risk of misconfiguration, unauthorized activity, and compliance issues. DigiCert® DNS’s RBAC capabilities help organizations prevent unauthorized or accidental changes, meet regulatory requirements, and maintain a clear audit trail. By leveraging these controls, teams can reduce outages, improve security posture, ensure accountability, and streamline internal and external audits.
Business benefit
Control access to critical changes: Ensure only authorized users can make sensitive DNS modifications.
Prevent costly mistakes: Enforce least privilege to avoid unauthorized or accidental changes.
Reduce risk across the board: Minimize misconfigurations, unauthorized activity, and compliance violations.
Simplify compliance and audits: Meet regulatory requirements and streamline audit processes.
Track every change with confidence: Maintain a clear, comprehensive audit trail for accountability and visibility.
Overview
This use case centers on usage statistics and activity log analysis, providing insight into DNS performance, billing, and accounting.
Core capabilities
Business need
DNS performance is critical to the availability of digital services, making detailed usage statistics essential for understanding traffic and verifying DNS changes. DigiCert® DNS’s comprehensive reporting provides insights into service demand, highlights abnormal usage, supports troubleshooting and optimization, and confirms change propagation. Its log retention and analysis capabilities also support audit readiness, compliance, and forensic investigations.
Business benefit
Verify DNS changes through usage data: Confirm that updates are reflected correctly in usage patterns to avoid downtime or misrouting.
Maintain uninterrupted service availability: Use usage statistics to track service demand and ensure resources meet user needs consistently.
Identify potential issues early: Analyze usage trends to spot unusual activity that may indicate emerging problems.
Respond proactively to disruptions: Leverage usage insights to detect deviations from normal behavior and minimize user impact.
Gain a deeper understanding of DNS activity: Access detailed usage reports and logs to uncover abnormal patterns and support informed decision-making.
Overview
This use case focuses on securely replicating DNS zone data between authoritative servers through zone transfers. It covers configuring primary and secondary IP sets to control which systems can send and receive data.
Core capabilities
Business need
Reliable zone transfers are essential for maintaining consistent DNS records across multiple servers or locations. By managing zone transfers through DigiCert® DNS, organizations can ensure data integrity, enforce transfer permissions, and reduce the risk of misconfigurations or unauthorized access. This results in improved DNS reliability, simplified replication processes, and better control over distributed DNS infrastructure.
Business benefit
Ensure data consistency: Keep DNS records synchronized across all authoritative servers.
Reduce operational risk: Minimize human error and misconfigurations through controlled access.
Simplify infrastructure management: Centrally manage IP permissions and transfer relationships.
Strengthen DNS security: Control who can access and replicate DNS zone data.
Support business continuity: Maintain availability and reliability of DNS services across failover or secondary environments.