Avoid single point-of-failure for our GeoIP domain

We don't want's DNS server to be a single-point-of-failure, so this commit adds multiple authoritative DNS servers for the zone. The extra DNS servers are run on the geomirror servers.

The _acme-challenge zone, used for obtaining certificates, is run solely on's DNS server, to avoid syncing DNS records between the servers (KISS).

