en / hr
Dinio DNS · private preview

Authoritative DNS hosting,
plus the security layer it should ship with.

Geo-routing, health checks, and weighted load balancing on the hosting side. Domain and IP-based filtering on the security side. One API, one platform, built to survive losing a region.

In testing now, launch approaching — we're planning limited free access for our first cohort of users.

[ 01 ] Authoritative hosting

DNS hosting with routing logic built in.

Beyond records and zones — traffic control that usually needs a separate product.

01
Geo-based routing
Route queries to different targets based on where the request is coming from.
02
Geo-blocking
Deny resolution for specific countries or regions at the DNS layer.
03
Health checks & failover
Routing decisions informed by live resource health, not static assumptions.
04
Weighted load balancing
Split traffic by ratio across targets — Server A 30%, Server B 70%, and so on.
05
Private zones & records
Internal zones that don't need to be, and aren't, publicly resolvable.
06
Metrics & anomaly detection
Traffic analytics and query metrics, with systems watching for abnormal patterns.
[ 02 ] Filtering & security

DNS-layer filtering, self-hosted-grade control.

The category PiHole and NextDNS popularized — built as part of the same platform, not bolted on.

01 · Lists
Blacklists & whitelists
Domain-level allow and deny policies, scoped per zone or network.
02 · Sources
Public blocklist filtering
Filter traffic against IP addresses sourced from public threat blocklists.
03 · Format
Domains, wildcards, regex
Lists aren't limited to exact matches — wildcard and regex patterns are supported.
04 · Scope
Per-zone policies
Different filtering rules for different zones or networks on the same account.
dinio cli
$ dinio policy block --list threat-intel --zone bitelex.com # 12,402 domains loaded policy active in 88ms
[ 03 ] Platform

One platform underneath both services.

Hosting and filtering share the same geo-distributed nodes, control plane, and data plane.

01
Geo-distributed nodes
Multiple regions serving queries, so no single location is a single point of failure.
02
Disaster-resilient by design
Control plane and data plane built to keep resolving even when a region goes down.
03
Full API access
Everything in the panel is available through the API — records, policies, metrics.
04
DoH & DoT support
Encrypted resolution over DNS-over-HTTPS and DNS-over-TLS.
05
Panel & support
A management panel for people who don't want to live in the API, and support behind it.
06
Privacy & GDPR alignment
Built with data minimization and GDPR alignment in mind, not retrofitted after the fact.
[ 04 ] Where this goes

DNS as the first layer, not an afterthought.

Three bets we're building toward.

01 / Security

DNS as the first line of defense.

Threats keep getting caught further downstream than they should. We think filtering and anomaly detection belong at the DNS layer, before a request ever reaches an application.

02 / Scale

Built for IPv6 and IoT growth.

Address space and device counts are both growing fast. Dinio is built to stay comfortable with both, not patched to tolerate them.

03 / Edge

Part of the move to the edge.

Compute keeps moving closer to users and further from any single data center. We want Dinio to be infrastructure that fits naturally into that shift — however it gets abstracted, from IaaS to FaaS.

Two ways in

Working on infrastructure — or want us to work on yours?

Join the Dinio DNS private preview, or send a short brief about what you're building. Either gets a thoughtful reply within two business days.