Mar 25, 2026 — Edge DNS and Shield NS53 updates

Edge DNS

This release includes these updates:

  • Multi-signer DNSSEC support. Multi-signer provides RFC 8901 Model 2 support. This feature allows multiple DNS providers to DNSSEC sign a zone configuration. The capability offers DNSKEY support for third parties. It includes a webhook setting that notifies a URL when new DNSKEYs are available for other providers to pull and add to their configuration. The Akamai GitHub library provides an example notification receiver.

  • Infrastructure Security Analytics ROI report. The new attacks summary report provides visibility into the number of attacks and the total duration of attacks across App and API Security, Edge DNS, and Prolexic.

  • Infrastructure Security Analytics in Control Center main menu. Infrastructure Security Analytics is now available as a menu item in the DNS SOLUTIONS category of Control Center. The Infrastructure Security Analytics solution does not require an Edge DNS entitlement to exist in an account’s contract.

  • Infrastructure Security Analytics graph annotations. Infrastructure Security Analytics reports now include annotations for events such as NXDOMAIN spikes.

  • Infrastructure Security Analytics expirations. All policies or configurations, such as dangling CNAME detection have an expiration of one year into the future. After one year, the configuration automatically disables. The system generates notifications for expiring configurations.

  • Infrastructure Security Analytics event snooze. To reduce activity and alarm fatigue, you can now snooze dangling CNAMES for 30 days or hide results for dangling CNAMES and DNS hijacking.

  • Infrastructure Security Analytics bulk actions. You can now enable and disable configurations for all zones in the current viewable list.

  • Infrastructure Security Zone Protection Freemium. Infrastructure Security Analytics allows you to monitor up to five domains. For these five domains, the service publishes a list of lookalike domains with metadata about each lookalike domain. To monitor more domains, consider any of these additional Akamai solutions:

    • DNS Posture Management. Allows monitoring of up to 25 domains.
    • Brand Guardian. Does not have any limits on domains you can monitor.

    For more on these solutions, contact your Akamai representative.

Shield NS53

This release includes these updates:

  • FQDNs for service IPs. Shield NS53 automatically assigns service names for its VIPs. These names have static IPv4 and IPv6 addresses.
  • Active Healthchecks. You can automatically run a health check for the origin name servers used within a Shield configuration.
  • Infrastructure Security Analytics destination for NXDOMAIN spike events. A tab is now available for shields within the Infrastructure Security Analytics solution. Each item in the tab corresponds to a shield and indicates any NXDOMAIN spike occurrence within the last 24 hours. You can send data on detected NXDOMAIN spikes for a shield to a third-party SIEM or IT service management solution.