Berlin's deSEC Hardens Web Security With Free, Mandatory DNSSEC Hosting
The non-profit removes financial and technical barriers to DNSSEC, protecting domains from spoofing and cache poisoning.
The Berlin-based non-profit deSEC is offering free, secure DNS hosting to the public to close a critical security gap in domain name system management. By mandating DNSSEC for all hosted information, the service makes high-level infrastructure security accessible to everyone, regardless of budget.
Operating entirely on free and open-source software, deSEC provides a hosting environment where all DNS information is signed with DNSSEC using elliptic-curve cryptography. The service supports a wide array of modern record types, including HTTPS, SVCB, CDNSKEY, CDS, OPENPGPKEY, SMIMEA, and TLSA. To maintain its operations, the organization has received support from the NLnet Foundation and RIPE NCC.
The DNSSEC Maturity Gap
DNS security has historically been treated as an optional feature or a premium add-on in commercial hosting environments. This has created a "DNSSEC Maturity Gap," where the technical and financial costs of implementing secure DNS prevent many individual developers and smaller organizations from protecting their domains. By automating the process and removing the cost, deSEC provides a security-first alternative that simplifies the deployment of DNSSEC and DANE (TLSA).
Hardening Global Infrastructure
This shift toward mandatory signing is critical for the stability of the internet. DNSSEC prevents common vulnerabilities such as DNS spoofing and cache poisoning, where attackers redirect users to fraudulent websites by forging DNS responses. By providing a free path to adoption, deSEC helps harden the global DNS infrastructure.
Furthermore, the service integrates with industry-standard tools like Terraform and Let's Encrypt. This ensures that high-security DNS can be scaled for large hosters or managed easily by solo developers without compromising privacy for commercial interests. By removing the friction of manual configuration, the service transforms a complex cryptographic process into a baseline utility.
Future Outlook
As more users migrate to security-mandated hosting, the industry may see a broader shift toward treating DNSSEC as a baseline requirement rather than a luxury. While the service continues to expand its reach, the long-term goal remains the widespread adoption of signed DNS records to eliminate the systemic risks associated with unauthenticated DNS traffic. This movement toward a signed-by-default web reduces the attack surface for millions of users and stabilizes the root of internet trust.