Skip to main content
Cloud / Azure / Products / Azure DNS Private Resolver - Hybrid DNS Resolution

Azure DNS Private Resolver - Hybrid DNS Resolution

Azure DNS Private Resolver: managed DNS resolution between Azure VNets and on-premises, with inbound and outbound endpoints and DNS forwarding rulesets.

networking
Pricing Model Billed per the Azure DNS pricing page
Availability Regional availability per 'Azure Products by Region - Azure DNS'
Data Sovereignty Customer data is not moved or stored outside the region where the resolver is deployed
Reliability per provider / see official documentation SLA

What is Azure DNS Private Resolver?

Azure DNS Private Resolver is a fully managed, highly available service that enables secure and seamless DNS resolution between Azure virtual networks and on-premises environments, without deploying, managing, or patching custom DNS servers. It facilitates hybrid network connectivity and simplifies network management for enterprise scenarios.

The resolver requires an Azure Virtual Network. When you create one, you also create one or more inbound endpoints that serve as the destination for DNS queries. The outbound endpoint processes DNS queries based on a DNS forwarding ruleset you configure; queries initiated in linked networks can be sent to other DNS servers. You don’t need to change DNS client settings on your virtual machines.

Resolution follows a fixed order: custom DNS servers configured for the virtual network apply first, then private DNS zones linked to the same virtual network, then virtual network links for DNS forwarding rulesets. If no suffix matches, Azure DNS resolves the query; when multiple matches exist, the longest suffix wins. DNS resolution between Azure virtual networks and on-premises networks requires Azure ExpressRoute or a VPN.

Core Features

  • Inbound endpoints for name resolution from on-premises through an IP address in the private VNet address space, statically or dynamically assigned
  • Outbound endpoints for conditional forwarding from Azure to on-premises, other cloud providers, or external DNS servers
  • DNS forwarding rulesets with up to 1,000 rules, linkable to multiple outbound endpoints and virtual networks
  • Virtual network links for name resolution in linked networks
  • Built-in high availability and zone redundancy
  • Deployment with Terraform, ARM template, or Bicep

Typical Use Cases

Resolving private DNS zones from on-premises
Enter the IP address of the inbound endpoint into your on-premises DNS conditional forwarder to resolve Azure private DNS zones from your own datacenter, for example for VMs using auto-registration or for Private Link enabled services.

Forwarding from Azure to on-premises
Through outbound endpoints and forwarding rulesets you route queries for specific domains to your internal DNS servers or to external resolvers.

Replacing your own DNS forwarder VMs
Instead of running, patching, and making DNS forwarders on virtual machines highly available, the managed service takes over that job.

Hybrid networks
In environments with ExpressRoute or VPN, the resolver provides consistent name resolution in both directions.

Benefits

  • Fully managed with built-in high availability and zone redundancy
  • Lower operating costs compared with self-operated IaaS solutions
  • Private access to your private DNS zones with conditional forwarding in both directions
  • High performance per endpoint with up to 10,000 queries per second
  • DevOps friendly: deployment with Terraform, ARM template, or Bicep
  • No changes required to DNS client settings on virtual machines

Integration with innFactory

As a Microsoft Solutions Partner, innFactory supports the design and operation of hybrid DNS architectures: sizing subnets, building inbound and outbound endpoints, structuring forwarding rulesets, and migrating existing DNS forwarder VMs.

We also verify the restrictions relevant to your environment, for example around encrypted VNets or Azure Lighthouse, and embed the solution in your landing zone architecture. Contact us for a no-obligation consultation.

Typical Use Cases

Resolving Azure private DNS zones from on-premises
Conditional forwarding from Azure to on-premises or external DNS servers
Replacing self-operated DNS forwarder VMs
Name resolution in hybrid networks over ExpressRoute or VPN

Technical Specifications

0th Inbound endpoints: destination for DNS queries from on-premises via an IP address from the VNet address space, static or dynamic
1st Outbound endpoints: conditional forwarding from Azure to on-premises, other cloud providers, or external DNS servers
2nd DNS forwarding rulesets with up to 1,000 rules, linkable to one or more outbound endpoints and virtual networks
3rd A forwarding rule consists of a domain name, a target IP address, and a target port and protocol (UDP or TCP)
4th When multiple matches are present, the longest suffix is used
5th Limits: 15 private resolvers per subscription, 5 inbound and 5 outbound endpoints per resolver, 500 VNet links per ruleset, 6 target DNS servers per rule, 10,000 QPS per endpoint
6th Subnet between /28 and /24, delegated exclusively to 'Microsoft.Network/dnsResolvers', not shareable between endpoints
7th A resolver references exactly one VNet in the same region; VNets with encryption enabled are not supported
8th No IPv6-enabled subnets, no ExpressRoute FastPath, no compatibility with Azure Lighthouse, no cross-tenant ruleset linking
9th Deployable with Terraform, ARM template, or Bicep

Frequently Asked Questions

Why do I need Azure DNS Private Resolver?

The service enables secure DNS resolution between Azure virtual networks and on-premises environments without deploying, managing, or patching custom DNS servers. It lets you resolve DNS queries for private DNS zones from anywhere.

What is the difference between inbound and outbound endpoints?

An inbound endpoint enables name resolution from on-premises or other private locations through an IP address that is part of your private virtual network address space; it receives DNS queries that ingress to Azure. An outbound endpoint enables conditional forwarding name resolution from Azure to on-premises, other cloud providers, or external DNS servers; those queries egress from Azure.

Which limits apply?

Microsoft lists 15 DNS private resolvers per subscription, 5 inbound and 5 outbound endpoints per resolver, 1,000 forwarding rules per ruleset, 500 virtual network links per ruleset, 2 outbound endpoints per ruleset, 6 target DNS servers per rule, and 10,000 QPS per endpoint. Endpoints require a dedicated subnet between /28 and /24 delegated exclusively to 'Microsoft.Network/dnsResolvers'.

Which restrictions should I be aware of?

VNets with encryption enabled don't support the service. A resolver can only reference one virtual network in the same region, and multiple resolvers can't share a virtual network. IPv6-enabled subnets are not supported, nor is ExpressRoute FastPath. Per Microsoft, the service isn't compatible with Azure Lighthouse, and rulesets can't be linked across tenants.

Does data stay in the region?

Microsoft states that Azure DNS Private Resolver doesn't move or store customer data outside the region where the resolver is deployed.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Ready to start with Azure DNS Private Resolver - Hybrid DNS Resolution?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation