<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[DNS providers offering DNSSEC (Swarm intelligence (and help) needed)]]></title><description><![CDATA[<p dir="auto">The german <a href="https://www.bsi.bund.de" target="_blank" rel="noopener noreferrer nofollow ugc">BSI</a> declares 2025 as <a href="https://themunicheye.com/bsi-email-security-2025-24867" target="_blank" rel="noopener noreferrer nofollow ugc">the Year for Email Security</a>.</p>
<p dir="auto">Most issues are resolved directly through the Cloudron platform. However, to fulfil all requirements, we need the support of our DNS service provider, as we rely on the service provider instead of operating our own DNS infrastructure.</p>
<p dir="auto">SPF / DKIM / DMARC – DNSSEC / DANE / TLS are the topics that the BSI deals with.</p>
<p dir="auto">Please help me find DNS service providers that offer DNSSEC to its customers.</p>
<p dir="auto">This is the result of my brief research:</p>
<ul>
<li>route53 (todo: research offer)</li>
<li>Namecheap (in their pro product)</li>
<li>Cloudflare (<s>todo: research offer</s>)</li>
<li>Gandi (seems to be supported only if the domain is managed directly by Gandi)</li>
<li>google cloud dns (todo: research offer)</li>
</ul>
<p dir="auto">I am interested in the offers. Is it possible to use only the DNS (e.g., as with DigitalOcean or Hetzner), or does the domain have to be transferred to the service provider's infrastructure? Is the service free or paid? Is it part of the DNS services supported by Cloudron or independent of them?</p>
<p dir="auto">The next step for me is to understand DANE. Maybe someone can help me with this topic too. <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=11345d81604" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>
]]></description><link>https://forum.cloudron.io/topic/14166/dns-providers-offering-dnssec-swarm-intelligence-and-help-needed</link><generator>RSS for Node</generator><lastBuildDate>Mon, 18 May 2026 09:41:24 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/14166.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 05 Aug 2025 21:47:24 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to DNS providers offering DNSSEC (Swarm intelligence (and help) needed) on Wed, 06 Aug 2025 19:43:01 GMT]]></title><description><![CDATA[<p dir="auto">I moved from Cloudflare to Infomaniak (registrar) + Bunny NET (DNS).<br />
DNSSEC works well.</p>
]]></description><link>https://forum.cloudron.io/post/111337</link><guid isPermaLink="true">https://forum.cloudron.io/post/111337</guid><dc:creator><![CDATA[nichu42]]></dc:creator><pubDate>Wed, 06 Aug 2025 19:43:01 GMT</pubDate></item><item><title><![CDATA[Reply to DNS providers offering DNSSEC (Swarm intelligence (and help) needed) on Wed, 06 Aug 2025 12:59:34 GMT]]></title><description><![CDATA[<p dir="auto">Desec is great but we hit issues when doing a restore onto a new IP address - we were locked out of <a href="http://desec.io" target="_blank" rel="noopener noreferrer nofollow ugc">desec.io</a> due to rate limiting</p>
<p dir="auto">We had a chat with the support and they suggested that cloudron could consider using their batch api to reduce the number of requests</p>
<p dir="auto">But as we need to be able to recover without  being locked out (out of hours) we switched to hetzner DNS instead.</p>
<p dir="auto">TLDR;  <a href="http://desec.io" target="_blank" rel="noopener noreferrer nofollow ugc">desec.io</a> are great,  the support is very good, however their rate limiting is somewhat aggressive and may catch you out in a bind.</p>
]]></description><link>https://forum.cloudron.io/post/111319</link><guid isPermaLink="true">https://forum.cloudron.io/post/111319</guid><dc:creator><![CDATA[nostrdev]]></dc:creator><pubDate>Wed, 06 Aug 2025 12:59:34 GMT</pubDate></item><item><title><![CDATA[Reply to DNS providers offering DNSSEC (Swarm intelligence (and help) needed) on Wed, 06 Aug 2025 07:26:08 GMT]]></title><description><![CDATA[<h1>Cloudflare</h1>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/luckow" aria-label="Profile: luckow">@<bdi>luckow</bdi></a> said in <a href="/post/111291">DNS providers offering DNSSEC (Swarm intelligence (and help) needed)</a>:</p>
<blockquote>
<p dir="auto">Cloudflare (todo: research offer)(todo: research offer)</p>
</blockquote>
<p dir="auto">Sine I am using Cloudflare for my private domains I can share some insights.<br />
Cloudflare even suggests on domain setup to enable and setup DNSSEC and it costs nothing.</p>
<pre><code>dig hackradt.com +dnssec +short
104.21.16.1
104.21.32.1
104.21.48.1
104.21.64.1
104.21.80.1
104.21.96.1
104.21.112.1
A 13 2 300 20250807081922 20250805061922 34505 hackradt.com. 15sxpjxH76bZmTRkYJdGr9vI9htfQjOVD0T303Q4BHI7UJbWUG4gK/IX UbLXyb4Tf30gJ/TaF8Q2T3DWYunuDQ==
</code></pre>
<pre><code>dig DNSKEY hackradt.com +short
256 3 13 oJMRESz5E4gYzS/q6XDrvU1qMPYIjCWzJaOau8XNEZeqCYKD5ar0IRd8 KqXXFJkqmVfRvMGPmM1x8fGAa2XhSA==
257 3 13 mdsswUyr3DPW132mOi8V9xESWE8jTo0dxCjjnopKl+GqJxpVXckHAeF+ KkxLbxILfDLUT0rAK9iUzy1L53eKGQ==
</code></pre>
<p dir="auto">and a trace</p>
<pre><code>dig DS hackradt.com +trace @1.1.1.1

; &lt;&lt;&gt;&gt; DiG 9.18.30-0ubuntu0.24.04.2-Ubuntu &lt;&lt;&gt;&gt; DS hackradt.com +trace @1.1.1.1
;; global options: +cmd
.                       517372  IN      NS      a.root-servers.net.
.                       517372  IN      NS      b.root-servers.net.
.                       517372  IN      NS      c.root-servers.net.
.                       517372  IN      NS      d.root-servers.net.
.                       517372  IN      NS      e.root-servers.net.
.                       517372  IN      NS      f.root-servers.net.
.                       517372  IN      NS      g.root-servers.net.
.                       517372  IN      NS      h.root-servers.net.
.                       517372  IN      NS      i.root-servers.net.
.                       517372  IN      NS      j.root-servers.net.
.                       517372  IN      NS      k.root-servers.net.
.                       517372  IN      NS      l.root-servers.net.
.                       517372  IN      NS      m.root-servers.net.
.                       517372  IN      RRSIG   NS 8 0 518400 20250819050000 20250806040000 46441 . jg9OLaEPRK9kCUHATy6mZXCba7eWr7cffsKnXOm+zKYyQf6QboUDiE69 veSbgvEpN/6wb9NxKcwTGN0phcpmH2ikVAC/9oNVAsOQ0h0li/AhC0sB jAZ+tfbk+Uah1M+8o5OSmHwXz48Iz3Kn4yisXMZ63ie6ZuON68WVfRDk p8VZ0QlG11wYIXiJ9/bbA1m6QYI5Ynl7pTfJQow1QRlreiHybh8hL0gZ USE12sdGoH1pZdUJ2WYPvHIof5ymKgbJDcz97PKy38M/phDHq13WqU3j s+3HY0YV8vpiPeyliwCzP1gywWwQfyfT1Mg4X4+DjjMf6JOWZwPvYXmy iTdrSQ==
;; Received 525 bytes from 1.1.1.1#53(1.1.1.1) in 11 ms

com.                    172800  IN      NS      b.gtld-servers.net.
com.                    172800  IN      NS      c.gtld-servers.net.
com.                    172800  IN      NS      g.gtld-servers.net.
com.                    172800  IN      NS      i.gtld-servers.net.
com.                    172800  IN      NS      l.gtld-servers.net.
com.                    172800  IN      NS      k.gtld-servers.net.
com.                    172800  IN      NS      h.gtld-servers.net.
com.                    172800  IN      NS      d.gtld-servers.net.
com.                    172800  IN      NS      a.gtld-servers.net.
com.                    172800  IN      NS      f.gtld-servers.net.
com.                    172800  IN      NS      e.gtld-servers.net.
com.                    172800  IN      NS      m.gtld-servers.net.
com.                    172800  IN      NS      j.gtld-servers.net.
com.                    86400   IN      DS      19718 13 2 8ACBB0CD28F41250A80A491389424D341522D946B0DA0C0291F2D3D7 71D7805A
com.                    86400   IN      RRSIG   DS 8 1 86400 20250819050000 20250806040000 46441 . JPvqL4brDkchFLnaQfHaaeTvLQL/zWvdmHI58oh5VgPV9UMIsjjvGfJ0 fWobwOd1eCAlVhsPFNHdGb5r82tJWj4tU41VMsXG4QVsBqpOgd4H9jcx OVWndh0xPbDGzQtcF7TuItUw1s3AxOGV34WzVLvjICdTfxyiHygVstDb 0VRYISSzxMJ/HDrqFva/5+b1yAqszWFgG92PlH71ww8ARIJhfPl2Kbi4 nY5zIHGcl5xqne/febdD7O8IvfL5B5baAY/ca+HgYp/nBgROD4rRslkn 7KCQdKUC65E27v5ZA60/l4ZqsBTx7Jbh8446umZSCiWs44b0iX4ez9d0 zgoPig==
;; Received 1200 bytes from 192.36.148.17#53(i.root-servers.net) in 14 ms

hackradt.com.           86400   IN      DS      2371 13 2 A186B81B9089ECB57752A20B7B6F70A54B9A7EC7722DB1A75C34EA33 F810E098
hackradt.com.           86400   IN      RRSIG   DS 13 2 86400 20250813022949 20250806011949 20545 com. IGGaC5MlqxDYc/Lz9D1GpMtTJF1apUu/HcYp1LK747msVxvXnyadooEw 9K42ELwb0ESD5QpdhetYN+nQkGy6sw==
com.                    172800  IN      NS      m.gtld-servers.net.
com.                    172800  IN      NS      g.gtld-servers.net.
com.                    172800  IN      NS      c.gtld-servers.net.
com.                    172800  IN      NS      i.gtld-servers.net.
com.                    172800  IN      NS      b.gtld-servers.net.
com.                    172800  IN      NS      k.gtld-servers.net.
com.                    172800  IN      NS      e.gtld-servers.net.
com.                    172800  IN      NS      j.gtld-servers.net.
com.                    172800  IN      NS      d.gtld-servers.net.
com.                    172800  IN      NS      f.gtld-servers.net.
com.                    172800  IN      NS      l.gtld-servers.net.
com.                    172800  IN      NS      a.gtld-servers.net.
com.                    172800  IN      NS      h.gtld-servers.net.
com.                    172800  IN      RRSIG   NS 13 1 172800 20250812002506 20250804231506 20545 com. c46CDTFjI2WMA5mRS+9duzqkVSh/ewmXqa5cGOCI/Y/8BbCulughdCFU vQOAyqicgA+3pAr4TVncozHUfwRc3w==
;; Received 1083 bytes from 192.33.14.30#53(b.gtld-servers.net) in 25 ms
</code></pre>
<p dir="auto">This can also be viewed in a flow chart with <a href="https://dnsviz.net/d/hackradt.com/dnssec/" target="_blank" rel="noopener noreferrer nofollow ugc">https://dnsviz.net/d/hackradt.com/dnssec/</a></p>
<p dir="auto"><img src="/assets/uploads/files/1754465135240-2db52277-6841-461d-9bdf-13009160c5c4-hackradt.com-2025-08-06-07_23_37-utc-resized.png" alt="2db52277-6841-461d-9bdf-13009160c5c4-hackradt.com-2025-08-06-07_23_37-UTC.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.cloudron.io/post/111311</link><guid isPermaLink="true">https://forum.cloudron.io/post/111311</guid><dc:creator><![CDATA[BrutalBirdie]]></dc:creator><pubDate>Wed, 06 Aug 2025 07:26:08 GMT</pubDate></item><item><title><![CDATA[Reply to DNS providers offering DNSSEC (Swarm intelligence (and help) needed) on Wed, 06 Aug 2025 04:57:06 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jdaviescoates" aria-label="Profile: jdaviescoates">@<bdi>jdaviescoates</bdi></a> You're welcome. It's been in the domain provider dropdown since last year (2024).</p>
]]></description><link>https://forum.cloudron.io/post/111305</link><guid isPermaLink="true">https://forum.cloudron.io/post/111305</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Wed, 06 Aug 2025 04:57:06 GMT</pubDate></item><item><title><![CDATA[Reply to DNS providers offering DNSSEC (Swarm intelligence (and help) needed) on Wed, 06 Aug 2025 04:40:00 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/robi" aria-label="Profile: robi">@<bdi>robi</bdi></a> sounds great, thanks for sharing.</p>
]]></description><link>https://forum.cloudron.io/post/111302</link><guid isPermaLink="true">https://forum.cloudron.io/post/111302</guid><dc:creator><![CDATA[jdaviescoates]]></dc:creator><pubDate>Wed, 06 Aug 2025 04:40:00 GMT</pubDate></item><item><title><![CDATA[Reply to DNS providers offering DNSSEC (Swarm intelligence (and help) needed) on Tue, 05 Aug 2025 23:07:38 GMT]]></title><description><![CDATA[<p dir="auto">Then it's good to take a look at the OSS <a href="https://deSEC.io" target="_blank" rel="noopener noreferrer nofollow ugc">https://deSEC.io</a></p>
<h1>DNSSEC</h1>
<p dir="auto">DNS information hosted at deSEC is <strong>signed with DNSSEC, always</strong>. We use state-of-the-art elliptic-curve cryptography. Besides following operational best practice, we adopt <a href="https://datatracker.ietf.org/doc/draft-ietf-dnsop-dnssec-bootstrapping/" target="_blank" rel="noopener noreferrer nofollow ugc">cutting-edge developments</a>.</p>
<h1>Cloud Integration</h1>
<p dir="auto">Thanks to <a href="https://talk.desec.io/t/tools-implementing-desec/11" target="_blank" rel="noopener noreferrer nofollow ugc">cloud integrations and language bindings</a>, deSEC works out of the box in automated environments. Examples include <strong>Terraform</strong> providers and <strong>Go, Python, and JavaScript bindings.</strong></p>
<h1>Modern Record Types</h1>
<p dir="auto">We support a <a href="https://desec.readthedocs.io/en/latest/dns/rrsets.html#supported-types" target="_blank" rel="noopener noreferrer nofollow ugc">broad array of record types</a>, including novel types such as <code>HTTPS</code>/<code>SVCB</code> (for <code>CNAME</code>-like behavior at the apex), <code>CDNSKEY</code>/<code>CDS</code> (RFC 8078, RFC 8901), or <code>OPENPGPKEY</code>, <code>SMIMEA</code>, and <code>TLSA</code>.</p>
<h1>Web Interface</h1>
<p dir="auto">We think we have the <strong>coolest GUI on the market</strong>. Thanks to <strong>real-time record validation</strong> and parsing, it is <strong>very intuitive and fast</strong> to use (even on mobile devices). Get started by importing your domain.</p>
<h1>REST API</h1>
<p dir="auto">Exert full control over your DNS via our <strong>modern API</strong> and benefit from advanced features such as bulk operations. It is <a href="https://desec.readthedocs.io/en/latest/dns/domains.html" target="_blank" rel="noopener noreferrer nofollow ugc">well-documented</a> and easily integrates into your scripts, tools, or CI/CD pipeline.</p>
<h1>Multi-Factor Auth (2FA)</h1>
<p dir="auto">Accidentally shared your password with someone? Enable MFA to <strong>keep your account safe</strong>. We currently support <strong>TOTP tokens</strong> (Authenticator app), with WebAuthn in the making.</p>
<h1>Scalability</h1>
<p dir="auto">Are you a web hoster? Start using deSEC, <strong>even with thousands of domains</strong>. Our global network ensures <strong>high availability and performance everywhere</strong>. <a href="mailto:support@desec.io" target="_blank" rel="noopener noreferrer nofollow ugc">Talk to us</a> about your use case.</p>
<h1>IPv6</h1>
<p dir="auto">deSEC is <strong>fully IPv6-aware</strong>: administration can be done using v6, AAAA-records containing IPv6 addresses can be set up, our name servers are reachable via IPv6.</p>
<h1>Fast Updates</h1>
<p dir="auto">Updates to your DNS information will be <strong>published world-wide within a few seconds</strong>. Minimum required TTLs are low.</p>
<h1>DANE / TLSA</h1>
<p dir="auto">Secure your web service with <code>TLSA</code> records, <strong>hardening it against fraudulently issued SSL certificates</strong>. You can also use other DANE techniques, such as <code>OPENPGPKEY</code> key exchange.</p>
<h1>Let's Encrypt Integration</h1>
<p dir="auto">We provide <strong><a href="https://pypi.org/project/certbot-dns-desec/" target="_blank" rel="noopener noreferrer nofollow ugc">easy integration</a> with Let's Encrypt</strong> and their certbot tool. <a href="https://talk.desec.io/t/tools-implementing-desec/11" target="_blank" rel="noopener noreferrer nofollow ugc">Further integration with other tools</a> like <a href="http://acme.sh" target="_blank" rel="noopener noreferrer nofollow ugc">acme.sh</a>, lego, and Terraform is available.</p>
<h1>Low-latency Anycast</h1>
<p dir="auto">We run <strong>global networks of high-performance frontend DNS servers</strong>. Your query is routed to the <strong>closest server</strong> via Anycast, so clients receive answers as fast as possible.</p>
<h1>Open Source</h1>
<p dir="auto">deSEC runs <strong>100% on free and open-source</strong> software. Start hacking away!</p>
<h1>Non-profit</h1>
<p dir="auto">deSEC is organized as a <strong>non-profit organization based in Berlin</strong>. We make sure that privacy is not compromised by business interest.</p>
]]></description><link>https://forum.cloudron.io/post/111297</link><guid isPermaLink="true">https://forum.cloudron.io/post/111297</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Tue, 05 Aug 2025 23:07:38 GMT</pubDate></item></channel></rss>