Overview
Overview of IBM NS1 Connect Managed DNS
Learn how IBM NS1 Connect delivers the authoritative DNS that makes applications and websites resilient, with intelligent traffic steering and multi CDN optimizaton.
Overview of IBM NS1 Connect Managed DNS
What is Traffic Steering
Simplify HTTPS Management
IBM NS1 Connect is a managed authoritative DNS and traffic steering service for applications deployed across AWS, multi-cloud, and hybrid environments. The service operates on a global anycast network spanning 26 points of presence (PoPs) across 6 continents and provides a 100% uptime SLA for DNS resolution.
It integrates with AWS services including Amazon EC2, Amazon EKS, Elastic Load Balancing (ALB/NLB), Amazon CloudFront, AWS Global Accelerator and Amazon CloudWatch.
NS1 Connect enables DNS-based traffic routing using real-time data such as Real user Metrics (RUM), third party QoE data, CloudWatch metrics, health checks, latency, geographic location, and application performance signals.
The platform supports primary and secondary DNS configurations across AWS, other cloud providers, and on-premises infrastructure.
Key Capabilities
Available and Adaptable
- Global anycast DNS network with 26 PoPs across 6 continents for distributed query handling - 100% uptime SLA for DNS resolution.
- Traffic steering using real-time metrics, health checks, latency, and RUM data.
- Multi-cloud and multi-CDN routing across AWS, other cloud providers, and on-prem environments.
Agile and Secure
- API-First integration with infrstructure-as-a-service (Kubernetes, Ansible, Piulimi) Kubernetes ExternalDNS, AWS services.
- Observability integrations including Amazon CloudWatch, Datadog, Splunk, AppDynamics, Catchpoint, ThousandEyes, Pingdom.
- Security features including DNSSEC, TSIG, IP allow-listing, RBAC, SAML/SSO, AWS IAM read-only integration.
- ISO/IEC 27001 certification. SOC 2 Type II available via AWS Vendor Insights.
Frequently Asked Questions
How does NS1 Connect integrate with Amazon Route 53?
AWS and IBM offer two complementary architecture patterns that help customers expand their use of Amazon Route 53 while meeting advanced performance and resiliency requirements. With IBM Cloud Sync (an optional add-on), zones, records, traffic-steering metadata, and health checks synchronize bidirectionally between NS1 Connect and Route 53 without DNS zone-transfer (XFR). Cloud Sync also backs up NS1 Connect DNS configurations to a customer-owned Amazon S3 bucket for fast restore.
Which AWS services are used for traffic steering decisions?
NS1 Connect ingests Amazon CloudWatch metrics directly into Filter Chains, so DNS answers reflect the live health and performance of Amazon EKS, EC2, ELB, CloudFront, and other AWS resources. In addition, the Filter Chain engine ingests telemetry from third-party observability and RUM providers (Datadog, Catchpoint, ThousandEyes, AppDynamics), enabling consistent multi-cloud and multi-provider decisioning. Cloud Sync backs up NS1 Connect DNS configurations to a customer-owned Amazon S3 bucket.
What scale does the service support?
Service tiers support query volumes from tens of millions per month to custom volumes at higher scales. NS1 Essentials handles 30-80M queries/month; NS1 Standard handles 50M-1B queries/month; NS1 Premium is custom-priced and scales beyond 1B/month.
Can NS1 Connect be used as primary or secondary DNS?
Yes. It can function as either a primary authoritative DNS provider or as a secondary provider.
What security features are included?
The platform is ISO 27001 certificatied with SOC 2 Type II available on request. It supports DNSSEC, TSIG, IP allow-listing, RBAC, SAML/SSO authentication and AWS IAM integration.
Does NS1 Connect support multi-CDN routing?
Yes. It can route traffic across Amazon CloudFront and third-party CDNs based on performance using real-time RUM, CloudWatch, Catchpoint and ThousandEyes signals, including cost-aware and contract-aware shaping.
Does NS1 support multi-cloud and hybrid environments?
Yes. Traffic routing policies can be applied across AWS, other public clouds, and on-premises infrastructure. Customers commonly run NS1 Connect as the global DNS decisioning layer in front of workloads spanning multiple providers, with per-zone or per-record steering policies. Where Amazon Route 53 is also in use, IBM Cloud Sync (optional add-on) keeps zones, records, and steering metadata aligned bidirectionally without DNS zone-transfer (XFR).
How does it fit DevOps workflows?
NS1 Connect provides API access and integrates with Terraform, Ansible, Pulumi, and Kubernetes ExternalDNS integration for automatic DNS record management; webhooks and APIs for CI/CD pipelines.
Is a free trial available?
Yes. A 30-day free trial is available through AWS Marketplace.
Highlights
- Global anycast network: Primary and secondary DNS built with a fully redundant architecture at 26 locations to meet a 100% uptime SLA.
- Real-time DNS traffic steering using Real User Metrics (RUM), Amazon CloudWatch metrics, third party QoE data, latency, and health checks.
- DevOps ready integrations with EC2, EKS, ALB/NLB, CloudFront, Terraform, Ansible, Pulumi, Global Accelerator, Datadog, Splunk, ThousandEyes.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Description | Cost/12 months |
|---|---|---|
Essentials | Includes 30M queries 1000 records 1 Filter Chain 2 Monitors | $1,188.00 |
Essentials Small Bundle | Includes 50M queries 1000 records 1 Filter Chain 2 Monitors | $2,388.00 |
Essentials Large Bundle | Includes 80M queries 1000 records 1 Filter Chain 2 Monitors | $4,188.00 |
Standard-50 | 50M Queries, 1000 Records, 1 Traffic Steering Filter Chains, 2 Monitors, 50 HTTPS Redirects, Spike Protection, Zone Backup/Restore | $4,188.00 |
Standard-150 | 150M Queries, 1000 Records, 3 Traffic Steering Filter Chains, 7 Monitors, 50 HTTPS Redirects, Spike Protection, Zone Backup/Restore | $9,426.00 |
Standard-250 | 250M Queries, 2000 Records, 25 Traffic Steering Filter Chains, 25 Monitors, 50 HTTPS Redirects, Spike Protection, Zone Backup/Restore | $21,106.80 |
Standard-500 | 500M Queries, 5000 Records, 50 Traffic Steering Filter Chains, 50 Monitors, 50 HTTPS Redirects, Spike Protection, Zone Backup/Restore | $31,096.80 |
Standard-1000 | 1Bn Queries, 10000 Records, 100 Traffic Steering Filter Chains, 100 Monitors, 50 HTTPS Redirects, Spike Protection, Zone Backup/Restore | $46,546.80 |
The following dimensions are not included in the contract terms, which will be charged based on your usage.
Dimension | Description | Cost/unit |
|---|---|---|
Overage Rate Total Queries (Requests) | Overage Rate Total Queries (Requests) | $50.00 |
Overage Rate DNS Records | Overage Rate DNS Records | $75.00 |
Overage Rate Filter Chains (Resource Units) | Overage Rate Filter Chains (Resource Units) | $103.50 |
Overage Rate Monitors (Jobs) | Overage Rate Monitors (Jobs) | $3.45 |
Overage Rate China Requests | Overage Rate China Requests | $172.00 |
Steering Standard Interaction Overage | Steering Standard Interaction Overage | $20.39 |
GSLB Standard Interaction Overage | GSLB Standard Interaction Overage | $20.39 |
Steering Advanced Interaction Overage | Steering Advanced Interaction Overage | $32.39 |
GSLB Advanced Interaction Overage | GSLB Advanced Interaction Overage | $32.39 |
Enterprise Request Overage | Enterprise Request Overage | $8.27 |
Vendor refund policy
All orders are non-cancellable and all fees and other amounts that you pay are non-refundable.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
Self Service on All tiers including Free Trial
Connect with your peers at IBM NS1 Connect Community. https://ibm.biz/Bdbz3K Review our comprehensive IBM NS1 Connect Documentation. https://ibm.biz/Bdbz3b
IBM Customer Support Engineer: Essentials, Standard and Premium Tiers
If you have IBM Advanced Support, you receive prioritized case handling and shorter response times. https://ibm.biz/Bdbz3J
Click below to open a case to submit a request for help from an experienced Customer Support Engineer.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.


Standard contract
Customer reviews
Powerful Dynamic DNS Routing, But a Learning Curve for Complex Policies
One situation where it became especially valuable for us was during high-traffic fintech onboarding campaigns and transaction-heavy operational windows where traffic spikes could impact application responsiveness across regions. Instead of relying on static DNS behavior, NS1 Connect allowed us to route traffic dynamically based on latency, health checks, and infrastructure availability. That flexibility helped maintain much more stable user experiences during peak usage periods.
What stood out immediately was the speed and responsiveness of DNS changes. During infrastructure incidents or deployment rollouts, traffic policies could be adjusted very quickly without waiting through slower propagation cycles that we had experienced with older DNS setups. For customer-facing systems where uptime and response consistency directly affect onboarding and transaction completion rates, that operational agility made a real difference.
From a usability perspective, the platform balanced enterprise-grade functionality with a relatively clean operational experience, which helped engineering and infrastructure teams collaborate more effectively during incident handling and rollout planning.
Overall, IBM NS1 Connect delivered strong value by improving traffic reliability, operational flexibility, and infrastructure responsiveness across critical production systems.
Another challenge we experienced was around operational visibility during highly customized routing scenarios. The monitoring and analytics capabilities are strong overall, but when troubleshooting complex traffic behavior across multiple providers, regions, and failover policies, identifying the exact cause of routing anomalies occasionally required deeper manual analysis than expected.
From a UI/UX perspective, the platform is functional and infrastructure-focused, but some administrative workflows still feel more engineered toward experienced network teams than broader operational users. Teams unfamiliar with DNS operations faced a noticeable learning curve during onboarding, especially around advanced policy configuration and automation workflows.
The integrations with cloud and infrastructure ecosystems were valuable, but maintaining consistency across evolving deployment environments and automation pipelines required ongoing operational governance.
In one healthtech workflow, we were managing patient-facing appointment scheduling and teleconsultation systems that experienced highly uneven traffic spikes during specific hours and seasonal campaigns. Before implementing NS1 Connect, traffic routing was relatively static, so when one region or infrastructure cluster became overloaded, users started experiencing slower response times and intermittent service instability. IBM NS1 Connect helped us introduce dynamic traffic steering based on endpoint health and latency conditions, which improved platform responsiveness significantly during peak usage periods.
Another operational benefit came during infrastructure maintenance and unexpected outages. Previously, rerouting traffic during incidents required more manual intervention and slower DNS propagation handling. With NS1 Connect, failover decisions became much more automated and responsive, reducing disruption for end users accessing critical healthcare services.
We also used the platform in fintech-related environments supporting onboarding systems and transaction-heavy customer workflows across multiple cloud regions. During high-volume onboarding campaigns, traffic loads shifted unpredictably between regions, and maintaining low latency became important for customer conversion and operational reliability. NS1 Connect helped distribute traffic more intelligently across infrastructure endpoints instead of relying on rigid DNS policies.
A major advantage operationally was improved visibility into traffic behavior and infrastructure health. Engineering teams could proactively monitor routing conditions, endpoint performance, and failover events before issues escalated into customer-facing incidents.