Live data from Hacker News

deSEC – Free Secure DNS

desec.io

21–30 of 59 posts

Re: deSEC – Free Secure DNS

#21

We found deSEC to be the only affordable DNS supplier in the EU that complies with state of the art secure DNSSEC. Highly recommended.

> We found deSEC to be the only affordable DNS supplier in the EU that complies with state of the art secure DNSSEC. I mean, if your definition of "affordable" is free, then sure. But for the record there are other affordable EU suppliers who do DNSSEC: - Bunny DNS[0] is "free" – i.e. only subject to their minimum $1/month account spend fee. - RcodeZero is very affordable[1] plus added bonus it is run by the `.at` re…

One who doesn't is frustratingly Hetzner.

Re: deSEC – Free Secure DNS

#22

We found deSEC to be the only affordable DNS supplier in the EU that complies with state of the art secure DNSSEC. Highly recommended.

> We found deSEC to be the only affordable DNS supplier in the EU that complies with state of the art secure DNSSEC. I mean, if your definition of "affordable" is free, then sure. But for the record there are other affordable EU suppliers who do DNSSEC: - Bunny DNS[0] is "free" – i.e. only subject to their minimum $1/month account spend fee. - RcodeZero is very affordable[1] plus added bonus it is run by the `.at` re…

I happen to run an affordable EU supplier who does DNSSEC, and also AXFR (incoming and outgoing). I offer a free plan from time to time, but not at the moment to preserve resources for paying customer.

https://www.ptrdns.net/

Re: deSEC – Free Secure DNS

#25
post #11

I signed up and saw they only allowed a single subdomain for DDNS, with docs saying to contact support if you needed more. I emailed asking for just 1 more subdomain and support told me that for my usecase I should just use CloudFlare. So I did. No silly miniscule restrictions.

Similar story: asked for an increase and got told > […] our mission is to improve Internet security by increasing the adoption of DNSSEC. [We therefore expect users to enable DNSSEC for their domains. > Would you be willing to do that? Wanting to increase the adoption of DNSSEC is fair, but couldn’t this be all self-serve? It’s almost as if they don’t want people to use them.

They've actually just done that, your limit automatically gets increased if all your domains are secured.

Re: deSEC – Free Secure DNS

#26
post #4

Just use unbound

My solution was to self-host PowerDNS and then sign up for the free DNS mirroring from hurricane electric. That way, I can administer my DNS records any way I want (these days I usually just manually edit PowerDNS's sqlite database) and if/when my PowerDNS server goes down, hurricane electric is still serving my records so the domain keeps resolving fine.

Re: deSEC – Free Secure DNS

#27
post #25

Earlier quoted context omitted.

Similar story: asked for an increase and got told > […] our mission is to improve Internet security by increasing the adoption of DNSSEC. [We therefore expect users to enable DNSSEC for their domains. > Would you be willing to do that? Wanting to increase the adoption of DNSSEC is fair, but couldn’t this be all self-serve? It’s almost as if they don’t want people to use them.

They've actually just done that, your limit automatically gets increased if all your domains are secured.

That’s good to know! I was actually very excited when I first found them; I was surprised that there aren’t many free/open public DNS hosting services.

Re: deSEC – Free Secure DNS

#28
I have been using deSEC for a couple of years without any issues. I mostly just do not want my DNS handled by my registrar so that I can easily transfer domains without worrying about DNS as well, and I do not like how centralized the internet is becoming around Cloudflare.

Re: deSEC – Free Secure DNS

#30
post #14

We found deSEC to be the only affordable DNS supplier in the EU that complies with state of the art secure DNSSEC. Highly recommended.

DNSSEC support is an anti-feature, it is dead/dying and the faster we can unburden ourselves from it the faster we can move on to better solutions. https://sockpuppet.org/blog/2015/01/15/against-dnssec/

Rebuttal: https://easydns.com/blog/2015/08/06/for-dnssec/>
Post reply on HN