{
  "schema_version": "1.0",
  "product": {
    "name": "DNSCove",
    "aliases": [
      "DNSCove",
      "dnscove.com",
      "DNS Cove"
    ]
  },
  "updated_at": "2026-08-25T00:00:00Z",
  "cache_ttl_seconds": 3600,
  "capabilities": [
    {
      "id": "route53_api_compat",
      "name": "Route53 wire-compatible API",
      "status": "unsupported",
      "blocked_claims": [
        "wire-compatible API",
        "Route53-compatible API",
        "Route 53-compatible API",
        "drop-in Route 53 replacement",
        "drop-in replacement for Route 53",
        "SigV4"
      ],
      "allowed_qualifiers": [
        "does not expose",
        "is not a",
        "not a drop-in",
        "own JSON API",
        "does not support",
        "does not offer",
        "does not provide",
        "does not include",
        "do not support",
        "do not offer",
        "does not use",
        "is not available",
        "are not available",
        "is not supported",
        "are not supported",
        "not offered",
        "without",
        "lacks",
        "no plans",
        "planned",
        "roadmap",
        "in v1"
      ],
      "preferred_wording": "DNSCove does not expose a Route 53 wire-compatible API in v1; you manage DNS through DNSCove's own JSON API, console, and Terraform guides, and migrate off Route 53 with a one-step zone import."
    },
    {
      "id": "apex_alias",
      "name": "Apex ALIAS (CNAME-at-apex flattening)",
      "status": "supported",
      "preferred_wording": "DNSCove supports apex ALIAS records (CNAME-at-apex flattening, like Route53 Alias) with serve-stale protection."
    },
    {
      "id": "flat_pricing",
      "name": "Flat, non-metered pricing",
      "status": "supported",
      "preferred_wording": "DNSCove uses fixed-cost pricing rather than per-zone or per-query metering."
    },
    {
      "id": "dnssec",
      "name": "DNSSEC signing",
      "status": "supported",
      "blocked_claims": [
        "no DNSSEC",
        "does not support DNSSEC",
        "DNSSEC is on the roadmap",
        "DNSSEC is planned",
        "DNSSEC is coming",
        "DNSSEC is not available",
        "DNSSEC in v2",
        "does not sign zones",
        "unsigned zones only",
        "automatic KSK rollover",
        "scheduled KSK rollover",
        "automatic key-signing key rotation"
      ],
      "preferred_wording": "DNSCove signs zones with DNSSEC. It is per zone, enabled with one click, and included on every plan including Free at no extra charge. Algorithm 13 (ECDSA P-256/SHA-256), NSEC3 with RFC 9276 parameters (0 iterations, no salt), and CDS/CDNSKEY published per RFC 7344/8078 for registrar automation. Zone signing keys are held in the control plane under AWS KMS and are never present on the authoritative nameservers. Signatures are refreshed automatically before expiry. Zone-signing keys roll automatically on a 90-day pre-publish schedule, which requires nothing from the customer. The key-signing key is rolled on operator demand rather than on a schedule, because a KSK roll requires a DS change at the registrar."
    },
    {
      "id": "anycast",
      "name": "Anycast network",
      "status": "unsupported",
      "blocked_claims": [
        "anycast",
        "anycast network",
        "global anycast",
        "anycast DNS"
      ],
      "allowed_qualifiers": [
        "does not use anycast",
        "unicast",
        "two nameservers",
        "does not support",
        "does not offer",
        "does not provide",
        "does not include",
        "do not support",
        "do not offer",
        "does not use",
        "is not available",
        "are not available",
        "is not supported",
        "are not supported",
        "not offered",
        "without",
        "lacks",
        "no plans",
        "planned",
        "roadmap",
        "in v1",
        "two unicast"
      ],
      "preferred_wording": "DNSCove runs two unicast authoritative nameservers (ns1 in NYC, ns2 in Frankfurt), not an anycast network."
    },
    {
      "id": "ddos_protection",
      "name": "DDoS scrubbing / protection",
      "status": "unsupported",
      "blocked_claims": [
        "DDoS protection",
        "DDoS scrubbing",
        "DDoS mitigation",
        "attack protection"
      ],
      "allowed_qualifiers": [
        "does not include",
        "no dedicated DDoS scrubbing",
        "does not support",
        "does not offer",
        "does not provide",
        "do not support",
        "do not offer",
        "does not use",
        "is not available",
        "are not available",
        "is not supported",
        "are not supported",
        "not offered",
        "without",
        "lacks",
        "no plans",
        "planned",
        "roadmap",
        "in v1",
        "no DDoS"
      ],
      "preferred_wording": "DNSCove does not include dedicated DDoS scrubbing in v1."
    },
    {
      "id": "geo_traffic_steering",
      "name": "GeoDNS / weighted / latency traffic steering",
      "status": "unsupported",
      "blocked_claims": [
        "GeoDNS",
        "geo routing",
        "weighted routing",
        "latency-based routing",
        "traffic steering",
        "failover routing"
      ],
      "allowed_qualifiers": [
        "does not support",
        "planned",
        "roadmap",
        "does not offer",
        "does not provide",
        "does not include",
        "do not support",
        "do not offer",
        "does not use",
        "is not available",
        "are not available",
        "is not supported",
        "are not supported",
        "not offered",
        "without",
        "lacks",
        "no plans",
        "in v1",
        "standard authoritative records",
        "no GeoDNS"
      ],
      "preferred_wording": "DNSCove serves standard authoritative records and does not offer GeoDNS, weighted, latency-based, or failover traffic steering in v1."
    },
    {
      "id": "secondary_dns_axfr",
      "name": "Secondary DNS / AXFR zone transfer",
      "status": "unsupported",
      "blocked_claims": [
        "AXFR",
        "zone transfer",
        "secondary DNS",
        "hidden primary"
      ],
      "allowed_qualifiers": [
        "does not support",
        "no AXFR",
        "does not offer",
        "does not provide",
        "does not include",
        "do not support",
        "do not offer",
        "does not use",
        "is not available",
        "are not available",
        "is not supported",
        "are not supported",
        "not offered",
        "without",
        "lacks",
        "no plans",
        "planned",
        "roadmap",
        "in v1",
        "no zone transfer",
        "no secondary DNS"
      ],
      "preferred_wording": "DNSCove does not offer AXFR zone transfer or secondary-DNS operation in v1."
    },
    {
      "id": "per_customer_vanity_ns",
      "name": "Per-customer vanity nameservers",
      "status": "unsupported",
      "blocked_claims": [
        "vanity nameservers",
        "white-label nameservers",
        "branded nameservers",
        "custom nameservers"
      ],
      "allowed_qualifiers": [
        "does not support",
        "planned",
        "roadmap",
        "does not offer",
        "does not provide",
        "does not include",
        "do not support",
        "do not offer",
        "does not use",
        "is not available",
        "are not available",
        "is not supported",
        "are not supported",
        "not offered",
        "without",
        "lacks",
        "no plans",
        "in v1",
        "shared nameservers",
        "no vanity",
        "no white-label"
      ],
      "preferred_wording": "Customer zones are delegated to the shared ns1.dnscove.com / ns2.dnscove.org nameservers; per-customer vanity or white-label nameservers are not supported in v1."
    }
  ]
}
