---
title: "STACKIT DNS Resolver"
description: "Recursive, internal DNS resolver providing DNSSEC validation and DNS over HTTPS (DoH) inside STACKIT VPCs."
scfAsset:
  category: "service"
  managed: false
  marketplaceUrl: "https://marketplace.stackit.cloud/en/products"
  tags: ["DNS Resolver", "DNSSEC", "Networking", "DoH"]
  maintainers:
    - user: "alexander.gabert"
source_url: "https://framework.stackit.cloud/architecture/assetcontainer/stackit/stackit-service-dns-resolver/"
source_file: "docs/architecture/assetcontainer/stackit/stackit-service-dns-resolver.mdx"
---

STACKIT DNS Resolver handles outbound recursive domain resolution for internal cloud workloads.

## Service Overview
- **Sovereign Resolution**: Keeps internal cloud DNS traffic inside STACKIT data center boundaries.
- **Enhanced Security**: Built-in DNSSEC validation and DNS over HTTPS (DoH) support prevent eavesdropping.
- **Zero Cost**: Provided as an integrated, free network platform component.

## Technical Details
- **Protocols**: Standard DNS over UDP/TCP (port 53) and DoH (RFC 8484).
- **Deployment**: Regional redundant IP endpoints with local response caching.

## Limitations & Constraints
- **Workload Scoped**: Intended strictly for internal STACKIT VM/SKE workloads; unavailable as a public resolver.

<LinkCard title="STACKIT DNS Resolver Documentation" href="https://docs.stackit.cloud" />
