DNS management
without the chaos
Approval workflows, drift detection, and full audit logging across every DNS provider — deployed in your environment.
| # | Type | Name | Value | Domain | Action | By | When | Status |
|---|---|---|---|---|---|---|---|---|
| 147 | A | app | 10.2.40.12 | app.acme.com | create | dfarber | 2 min ago | applied |
| 146 | CNAME | api | lb-prod.us-east-1.aws | api.acme.com | update | jpostel | 14 min ago | pending |
| 145 | MX | 10 mx1.acme.com | mail.acme.com | create | dterry | 1 hr ago | applied | |
| 144 | CNAME | cdn | d3x7k.cloudfront.net | cdn.acme.com | update | mpainter | 3 hr ago | approved Scheduled |
| 143 | TXT | _dmarc | v=DMARC1; p=reject; rua=… | acme.com | create | driggle | 5 hr ago | applied |
| 142 | A | vpn | 203.0.113.50 | vpn.acme.com | delete | dfarber | 6 hr ago | pending |
| 141 | AAAA | ingress | 2001:db8::1 | k8s.acme.com | create | jpostel | 8 hr ago | applied |
| 140 | SRV | _sip._tcp | 10 5 5060 pbx.acme.com | sip.acme.com | update | mpainter | 1 day ago | applied |
From request to production in a controlled flow
Every DNS change follows the same auditable path — no shortcuts, no surprises.
Submit
Any team member submits a DNS change request. Pre-flight checks warn of conflicts instantly.
Review
An independent approver reviews the change. One-click approve from Slack, Teams, or email.
Apply
Approved changes execute against the correct provider — immediately or on schedule.
Verify
Drift detection confirms the change took effect. Full audit trail from start to finish.
One interface. Every provider.
End users pick a domain and submit. Netra routes the change to the right provider automatically. No one needs to know where the zone lives.
Windows DNS
Server 2016–2025. Multi-DC failover, zone transfers, seamless integration with your existing infrastructure.
AWS Route 53
Hosted zones, alias records, health checks. Full IAM integration.
GCP Cloud DNS
Managed zones, DNSSEC support, change batching. Works with your existing GCP projects.
Azure DNS
DNS zones, record sets, and private DNS zone support. Native Azure integration.
Cloudflare
Managed DNS with API token authentication. Zone management, record CRUD, and automatic TTL handling.
Built for teams that take DNS seriously
Enterprise-grade capabilities that bring change control, visibility, and automation to your DNS operations — built for platform engineering teams.
Approval Workflows
Two-person rule by default. Submitters can't approve their own requests. Bypass is audit-logged.
Drift Detection
Periodic comparison of live DNS vs applied requests. Get alerted when records diverge from what was approved.
Audit Logging
Immutable record of every action. Export to CSV, forward to your SIEM of choice in real-time.
SSO & RBAC
LDAP/Active Directory, Okta, Microsoft Entra ID, or any OIDC provider. Three-tier roles with group-based mapping.
Alerting & Approvals
One-click approve/reject from Slack and Teams. Severity-mapped alerts to PagerDuty and Opsgenie. 7 notification channels with retry and backoff.
Rollback
One-click rollback on any applied request. Creates an inverse change and applies it immediately — fully audit-logged.
Zone Browser
Import, browse, search, and export all records. Auto-sync keeps the view current. CSV and BIND export.
Scheduled Changes
Approve DNS changes during business hours, schedule them to apply during maintenance windows. Timezone-aware, environment-scoped — no one gets paged.
Built for regulated environments
Netra enforces separation of duties, encrypts credentials at rest, and produces the audit trail your compliance team needs.
Separation of duties
Enforced two-person rule ensures no single individual can submit and approve a production change.
Zero data egress
Runs entirely within your network. No telemetry, no external dependencies, no data leaves your environment.
Encryption at rest
All stored credentials protected with AES-256-GCM. Session tokens cryptographically signed.
Immutable audit trail
Every action logged with user, timestamp, and IP. Exportable to CSV. Real-time forwarding to your SIEM.
SOC 2 & ISO 27001 aligned
Change management controls, access logging, and retention policies that support your compliance posture.
Enterprise identity
LDAP/Active Directory, Okta, Entra ID, or any OIDC provider. Role-based access with group mapping and session controls.
IP allowlist
CIDR-based network access control. Restrict who can reach Netra by IP range — no VPN required for access enforcement.
Change ticket requirements
Require a Jira, ServiceNow, or internal ticket reference on every DNS submission. Scoped per environment — enforce for production, optional for dev.
Works with what you already run
Netra connects to your CI/CD pipelines, ITSM platforms, identity providers, and observability stack — no rip-and-replace required.
CI/CD Pipelines
Automate DNS changes as part of deployments. Native support for GitHub Actions, GitLab CI/CD, Bitbucket Pipelines, and Azure DevOps.
Terraform Provider
Manage DNS as infrastructure-as-code. Integrates with your existing IaC review and approval process.
ITSM & Automation
Structured webhook payloads for ServiceNow, Ansible, and CMDB sync. Trigger downstream workflows on every change.
Slack & Teams
Approve or reject requests directly from your team's communication channels — no context switching required.
SIEM & Observability
Real-time audit event forwarding to Splunk, Elastic, Datadog, or any syslog/HTTP collector.
REST API
Full API with named, revocable tokens. Build custom integrations, dashboards, or connect to internal tooling.
Your environment. Your rules.
Netra runs inside your network perimeter — on-prem, private cloud, or managed cloud. We handle the deployment planning so your team can focus on operations.
On-Premises
Full network isolation behind your firewall. No internet access required after initial image pull.
Kubernetes
Helm chart with production defaults. Fits your existing cluster operations, ingress, and monitoring.
AWS / Azure / GCP
Native deployment on ECS, Container Apps, or Cloud Run. Integrates with your cloud's IAM and networking.
Hybrid
Manage on-prem Windows DNS and cloud-hosted zones from a single instance — wherever it makes sense to run.
Ready to evaluate?
Our team provides guided deployment planning, architecture review, and hands-on onboarding tailored to your environment. Most organizations are live within a day.
What's included
- Architecture review and deployment planning
- SSO and provider configuration assistance
- Health monitoring and alerting setup
- Team onboarding and training
- Ongoing support and updates
Take control of your DNS operations
See how Netra brings approval workflows, drift detection, and full audit logging to your multi-provider DNS infrastructure.