Authoritative hardening
Validate hidden-primary posture, TSIG, XFR ACLs, DNS Cookies, response-rate limiting, and minimal-response controls.
New: Watch DNS in real-time — DNSsecured simulates resolver trust, DNSSEC, DANE, and traffic steering in one flow.
See how it worksOpen source infrastructure
DNSsecured helps teams ship safer DNS infrastructure with hardened resolver trust, DNS posture checks, DNSSEC and DANE validation, and decision engines for resilient traffic steering.
Watch DNSsecured process a live query path with policy checks in under a minute.
Terminal-style simulation inspired by Caddy demos. It runs DNSsecured commands and shows live security posture events.
Validate hidden-primary posture, TSIG, XFR ACLs, DNS Cookies, response-rate limiting, and minimal-response controls.
Use system DNS, custom UDP/TCP upstreams, DNS-over-TLS, or DNS-over-HTTPS with optional TLS pinning controls.
Run SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI, DNSSEC component validation, and DANE/TLSA verification.
Generate DNSSEC rollover plans and evaluate health/latency-aware steering decisions for reliable multi-endpoint traffic.
pkg/dnssecured - scanner and checkspkg/authoritative - hardening posturepkg/dnssec - rollover planningpkg/steering - decision engine