Last month we completed a rearchitecture of our Authoritative DNS edge network , bringing the entire cache edge network onto infrastructure we operate ourselves. Before explaining why and how we made that change, it’s worth understanding how the previous architecture came to be. In 2014, we were running our own anycast network across 5 points of presence, with hardware-based DDoS defense in front of it.