When customers point a domain at your hosting, what do they type into their registrar? If the answer is someone else's nameservers, part of your service still runs on another company's brand and infrastructure. Private nameservers, such as ns1.yourbrand.com and ns2.yourbrand.com, fix that. They make your hosting look established, keep DNS under your control, and let you change server IPs without asking every customer to update their domains.
This guide explains how authoritative DNS and private nameservers work, then walks through setting them up with Heimdall, the authoritative DNS server built into Unicorn Panel.
Authoritative DNS in plain terms
There are two kinds of DNS servers. Recursive resolvers answer questions for users: your laptop asks one "where is example.com?" and it goes and finds out. Authoritative servers hold the actual answers for a domain: the records that say where the website, mail and other services live.
When you host websites, you want to run the authoritative side for your customers' domains. That lets your control panel create and update records automatically as sites, mailboxes and certificates are created.
What private nameservers are
Private nameservers are authoritative DNS servers named under your own domain. Customers set their domain's nameservers to ns1.yourbrand.com and ns2.yourbrand.com, and your servers answer for those domains from then on.
There is one chicken-and-egg problem. To find ns1.yourbrand.com, a resolver would normally ask the nameservers for yourbrand.com, which are the very servers it is trying to find. Glue records solve this. You register your nameserver hostnames and their IP addresses with your domain registrar, and the registry publishes those IPs directly. Most registrars call this registering "child nameservers" or "private nameservers".
Why run at least two nameservers
If your only nameserver goes down, every domain it serves disappears from the internet, even if the web servers are perfectly healthy. Running two or more nameservers on separate servers, ideally in different locations or networks, gives you redundancy. Customers also get faster answers when a nearby nameserver responds.
This is where a multi-server control panel helps. Unicorn Panel's Heimdall replicates zones across multiple hosts (DNS1, DNS2 or more), so your customers get real authoritative answers from geographically diverse servers. Learn how the fleet model works in our multi-server pillar guide.
What Heimdall DNS gives you
Heimdall is our own authoritative DNS server, built into the panel rather than bolted on. The DNS page has the full feature list; in short:
| Feature | What it does |
|---|---|
| Record types | A, AAAA, MX, TXT, CNAME, SRV, CAA, NS and PTR, managed per zone |
| Multi-host replication | Zones replicate to every nameserver host in the fleet |
| Auto records | Creating a site on a panel-managed domain adds its A record automatically |
| Sub-site dedup | Adding blog.example.com does not re-add the apex record of example.com |
| DNS preflight | DNS is checked before every SSL issuance so certificate attempts are not wasted |
| Mail records | SPF and DMARC are written into the zone when the domain's mail is on the panel |
| Query metrics | Query rates per zone and cache-hit ratios shown in the panel |
| DNSSEC | Optional |
Setting up private nameservers with Unicorn Panel
These steps follow the documentation. You need two servers running Unicorn Panel, each with its own public IP address, and a domain for your nameservers.
1. Install the Heimdall DNS role. In the Primary panel, go to Servers, choose the first DNS server, open Roles and install Heimdall DNS. Once it is enabled, a Nameservers (DNS) option appears under Settings.
2. Set the first server as Master. On the first DNS server, make sure its Server Type is set to Master.
3. Prepare the second server. Install Unicorn Panel on a second fresh server and note its IP address.
4. Register glue records. At your domain registrar, register ns1.yourbrand.com with the first server's IP and ns2.yourbrand.com with the second server's IP.
5. Add your domain and nameserver A records. On the first server, add yourbrand.com in Domains if it is not there yet, then create A records for ns1 and ns2 pointing at the matching IPs.
6. Enter the nameservers. On the first server's Domains screen, set Master Server to ns1.yourbrand.com and 2nd Nameserver to ns2.yourbrand.com. The panel validates the records and retrieves their IPs; if it succeeds, it updates all DNS records to use your nameservers from then on. If validation fails because glue has not propagated, try again later.
7. Set the second server as Slave. On the second server, set Server Type to Slave and enter the Master nameserver. Synchronisation begins and can take around 60 seconds.
8. Open port 53. Make sure TCP and UDP port 53 are open on both servers, including any network firewall at your provider. The panel opens it on the host automatically when the role is installed.
You can force a full sync at any time with the Synchronize Zones link, and import existing zones by dragging in or pasting a zone file. Double-check imported records afterwards, as some records may not be compatible.
Testing your nameservers
Once everything is set up, confirm both servers answer authoritatively. From any machine with dig installed:
dig @ns1.yourbrand.com example.com A +norec
dig @ns2.yourbrand.com example.com A +norec
Both should return the same answer with the aa (authoritative answer) flag set. Then check that the registry has your glue:
dig ns1.yourbrand.com A
Finally, point a test domain's nameservers at ns1 and ns2 and wait for the registrar change to propagate.
Private nameservers and white-label hosting
Private nameservers are a key part of a professional hosting brand. Combined with a branded panel domain, branded SMTP and a branded mail hostname, they mean nothing your customers touch mentions anyone but you. Our guide to starting a white-label hosting reseller business covers the full picture.
DNS and email work together
Email deliverability depends on DNS. When a domain's DNS and mail both live on Unicorn Panel, the panel generates a per-domain DKIM key and writes SPF and DMARC records into the zone for you. See self-hosted email for web hosts for the mail side.
Frequently asked questions
Do I need two servers for private nameservers? You should have at least two, on separate machines, so DNS stays up if one fails. Unicorn Panel's free tier covers two servers.
What are glue records? IP addresses for your nameserver hostnames, registered at your registrar so resolvers can find nameservers that live inside the domain they serve.
Does Heimdall support DNSSEC? Yes, as an option.
Can I import zones from my old DNS provider? Yes. Drag and drop or paste a zone file, then review the imported records.
Will creating a website update DNS automatically? Yes. On panel-managed domains, the A record is added when the site is created.
Own your DNS
Running your own authoritative DNS gives you control, redundancy and a more professional brand. With Heimdall built into Unicorn Panel, it is a role you install, not a separate system to maintain.
wget -qO- https://unicornpanel.com/install | sh
Learn more about Heimdall DNS or try the live demo.