home.social

#nameservers — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #nameservers, aggregated by home.social.

  1. desec.io seems to be serving as authoritative name servers for nic.af ie registry operator site for .af ccTLD.

    See bgp.tools/dns/nic.af

    #nameservers #af

  2. desec.io seems to be serving as authoritative name servers for nic.af ie registry operator site for .af ccTLD.

    See bgp.tools/dns/nic.af

    #nameservers #af

  3. desec.io seems to be serving as authoritative name servers for nic.af ie registry operator site for .af ccTLD.

    See bgp.tools/dns/nic.af

    #nameservers #af

  4. desec.io seems to be serving as authoritative name servers for nic.af ie registry operator site for .af ccTLD.

    See bgp.tools/dns/nic.af

    #nameservers #af

  5. desec.io seems to be serving as authoritative name servers for nic.af ie registry operator site for .af ccTLD.

    See bgp.tools/dns/nic.af

    #nameservers #af

  6. Interesting, Netnod's (AS8674) 194.146.107.0/24 seems to be (also) a downstream of AS142502 which is "Bharat Public DNS" run by NIXI. bgp.he.net/super-lg/#194.146.1

    194.146.107.6 hosts n.de.net, one of the authoritative name servers for .de ccTLD.

    Bharat Public DNS by NIXI/Government of India runs recursive resolver on 1.10.10.10. Some details at blog.gauravkansal.in/2025/06/o

    #nameservers #dns #india

  7. Interesting, Netnod's (AS8674) 194.146.107.0/24 seems to be (also) a downstream of AS142502 which is "Bharat Public DNS" run by NIXI. bgp.he.net/super-lg/#194.146.1

    194.146.107.6 hosts n.de.net, one of the authoritative name servers for .de ccTLD.

    Bharat Public DNS by NIXI/Government of India runs recursive resolver on 1.10.10.10. Some details at blog.gauravkansal.in/2025/06/o

    #nameservers #dns #india

  8. I run my own #nameservers or #DNS if you will, and have done so for over 25 years. Initially based on #BIND (aka named) but I later moved to #PowerDNS, There are numerous frontends of varying quality available for PowerDNS. I have opinions on those, but this isn't about them.

    For the secondary name servers (in the old and less enlightened days known as slaves) I've always run the same software as the primary. First BIND, then PowerDNS. Recently though, I've been testing out what appears to be a much simpler alternative: #NSD by #Amsterdam based NLnet Labs.

    Using #CatalogZones - a new concept to me - I'm able to run secondaries with TSIG notifies and zone transfers as well as fully supported primary signed DNSSEC with a configuration of only 40 lines. No updates needed when adding or removing zones.

    For this to work well though, some configuration is required for each zone on the primary. With a little trigger and function magic, this can be automized by the database.

    Wheee!

  9. I run my own #nameservers or #DNS if you will, and have done so for over 25 years. Initially based on #BIND (aka named) but I later moved to #PowerDNS, There are numerous frontends of varying quality available for PowerDNS. I have opinions on those, but this isn't about them.

    For the secondary name servers (in the old and less enlightened days known as slaves) I've always run the same software as the primary. First BIND, then PowerDNS. Recently though, I've been testing out what appears to be a much simpler alternative: #NSD by #Amsterdam based NLnet Labs.

    Using #CatalogZones - a new concept to me - I'm able to run secondaries with TSIG notifies and zone transfers as well as fully supported primary signed DNSSEC with a configuration of only 40 lines. No updates needed when adding or removing zones.

    For this to work well though, some configuration is required for each zone on the primary. With a little trigger and function magic, this can be automized by the database.

    Wheee!

  10. Fancy, the authoritative nameservers for the xyz. TLD are as follows:

    x.nic.xyz
    y.nic.xyz
    z.nic.xyz
    generationxyz.nic.xyz

    How fun. I never thought of the #TLD as being a pun to demographic cohorts.

    #DNS #ICANN #nameservers

  11. Fancy, the authoritative nameservers for the xyz. TLD are as follows:

    x.nic.xyz
    y.nic.xyz
    z.nic.xyz
    generationxyz.nic.xyz

    How fun. I never thought of the #TLD as being a pun to demographic cohorts.

    #DNS #ICANN #nameservers

  12. Just scraping the #IANA assigned TLDs and the corresponding documented #nameservers. What I don't get is, why so many companies apply for a #TLD. It's not particularly cheap to apply for one of those ngTLDs, yet compared to the company sizes, it's probably pennies. Is it a prestige investment? Is it a digital resource to grab, before someone else does it?

    Other than #Microsoft, #Google, and #AWS, I've rarely seen any ngTLD representing a corporation's name to actually be used in practice.

    Does anyone in the #infosec community share their view?

    #askfedi #askmasto #askinfosec #DNS

  13. Just scraping the #IANA assigned TLDs and the corresponding documented #nameservers. What I don't get is, why so many companies apply for a #TLD. It's not particularly cheap to apply for one of those ngTLDs, yet compared to the company sizes, it's probably pennies. Is it a prestige investment? Is it a digital resource to grab, before someone else does it?

    Other than #Microsoft, #Google, and #AWS, I've rarely seen any ngTLD representing a corporation's name to actually be used in practice.

    Does anyone in the #infosec community share their view?

    #askfedi #askmasto #askinfosec #DNS

  14. Just scraping the #IANA assigned TLDs and the corresponding documented #nameservers. What I don't get is, why so many companies apply for a #TLD. It's not particularly cheap to apply for one of those ngTLDs, yet compared to the company sizes, it's probably pennies. Is it a prestige investment? Is it a digital resource to grab, before someone else does it?

    Other than #Microsoft, #Google, and #AWS, I've rarely seen any ngTLD representing a corporation's name to actually be used in practice.

    Does anyone in the #infosec community share their view?

    #askfedi #askmasto #askinfosec #DNS

  15. Just scraping the #IANA assigned TLDs and the corresponding documented #nameservers. What I don't get is, why so many companies apply for a #TLD. It's not particularly cheap to apply for one of those ngTLDs, yet compared to the company sizes, it's probably pennies. Is it a prestige investment? Is it a digital resource to grab, before someone else does it?

    Other than #Microsoft, #Google, and #AWS, I've rarely seen any ngTLD representing a corporation's name to actually be used in practice.

    Does anyone in the #infosec community share their view?

    #askfedi #askmasto #askinfosec #DNS

  16. Just scraping the #IANA assigned TLDs and the corresponding documented #nameservers. What I don't get is, why so many companies apply for a #TLD. It's not particularly cheap to apply for one of those ngTLDs, yet compared to the company sizes, it's probably pennies. Is it a prestige investment? Is it a digital resource to grab, before someone else does it?

    Other than #Microsoft, #Google, and #AWS, I've rarely seen any ngTLD representing a corporation's name to actually be used in practice.

    Does anyone in the #infosec community share their view?

    #askfedi #askmasto #askinfosec #DNS

  17. bgp.tools being served via 13 authoritative name servers (via 3 different providers + in house NS):

    ```
    $ dig +short ns bgp.tools
    ns1.exoscale.ch.
    ns-721.awsdns-26.net.
    ns-1329.awsdns-38.org.
    ns4-35.azure-dns.info.
    ns3-35.azure-dns.org.
    ns1.exoscale.io.
    ns-302.awsdns-37.com.
    ns-1799.awsdns-32.co.uk.
    ns1.exoscale.net.
    ns1-35.azure-dns.com.
    ns2-35.azure-dns.net.
    ns1.exoscale.com.
    backup-ns.bgp.tools.
    ```

    #bgptools #nameservers #dns

  18. @zenire @bert_hubert

    Qua Europese (anycast) nameserver hosters:

    - cloudns.net/ (Bulgaarse partij levert o.a. aan overheid)
    - desec.io/ (innovatieve Duitse non-profit)
    - netnod.se/dns (Zweedse operator van een van de root name servers)
    - rcodezero.at (verbonden aan Oostenrijkse TLD operator)

    Zie verder nog: european-alternatives.eu/categ (@european_alternatives).

    #DNS #nameservers

  19. @zenire @bert_hubert

    Qua Europese (anycast) nameserver hosters:

    - cloudns.net/ (Bulgaarse partij levert o.a. aan overheid)
    - desec.io/ (innovatieve Duitse non-profit)
    - netnod.se/dns (Zweedse operator van een van de root name servers)
    - rcodezero.at (verbonden aan Oostenrijkse TLD operator)

    Zie verder nog: european-alternatives.eu/categ (@european_alternatives).

    #DNS #nameservers

  20. In January 2023, #Cloudflare replaced #Verisign in providing #DNS #registry services for the .gov #TLD. Besides the registry, they also run the authoritative #nameservers.

    Verisign ran it for 12 years, and cost the #US #government apparently just half as much as Cloudflare charges ($7.2M).

    Verisign loses prestive .gov contract to Cloudflare

  21. In January 2023, #Cloudflare replaced #Verisign in providing #DNS #registry services for the .gov #TLD. Besides the registry, they also run the authoritative #nameservers.

    Verisign ran it for 12 years, and cost the #US #government apparently just half as much as Cloudflare charges ($7.2M).

    Verisign loses prestive .gov contract to Cloudflare

  22. Recently made the transition to self hosting authoritative name servers. Wrote a bit of secondary options available for it and the experience itself blog.sahilister.in/2025/07/sec

    Didn't found the process too hard TBF, worth a try.

    #authoritative #nameservers #dns #domains

  23. Recently made the transition to self hosting authoritative name servers. Wrote a bit of secondary options available for it and the experience itself blog.sahilister.in/2025/07/sec

    Didn't found the process too hard TBF, worth a try.

    #authoritative #nameservers #dns #domains

  24. Recently made the transition to self hosting authoritative name servers. Wrote a bit of secondary options available for it and the experience itself blog.sahilister.in/2025/07/sec

    Didn't found the process too hard TBF, worth a try.

    #authoritative #nameservers #dns #domains

  25. Recently made the transition to self hosting authoritative name servers. Wrote a bit of secondary options available for it and the experience itself blog.sahilister.in/2025/07/sec

    Didn't found the process too hard TBF, worth a try.

    #authoritative #nameservers #dns #domains

  26. Recently made the transition to self hosting authoritative name servers. Wrote a bit of secondary options available for it and the experience itself blog.sahilister.in/2025/07/sec

    Didn't found the process too hard TBF, worth a try.

    #authoritative #nameservers #dns #domains

  27. Case of (broken) maharashtra.gov.in Authoritative Name Servers blog.sahilister.in/2025/06/cas

    TLDR they're broken on multiple levels. Sync broken, RFC 1918 address, each NS giving different response - there's too much going on.

    #dns #authoritative #nameservers #india

  28. Case of (broken) maharashtra.gov.in Authoritative Name Servers blog.sahilister.in/2025/06/cas

    TLDR they're broken on multiple levels. Sync broken, RFC 1918 address, each NS giving different response - there's too much going on.

    #dns #authoritative #nameservers #india

  29. Case of (broken) maharashtra.gov.in Authoritative Name Servers blog.sahilister.in/2025/06/cas

    TLDR they're broken on multiple levels. Sync broken, RFC 1918 address, each NS giving different response - there's too much going on.

    #dns #authoritative #nameservers #india

  30. Case of (broken) maharashtra.gov.in Authoritative Name Servers blog.sahilister.in/2025/06/cas

    TLDR they're broken on multiple levels. Sync broken, RFC 1918 address, each NS giving different response - there's too much going on.

    #dns #authoritative #nameservers #india

  31. Good enough amount of name servers :P
    ```
    $ dig ns sahil.rocks +short
    ns2.afraid.org.
    marvin.sahilister.net.
    ns1.1984.is.
    ns0.1984.is.
    ns3.jing.rocks.
    colin.sahilister.net.
    puck.nether.net.
    ns2.albony.in.
    ns-global.kjsl.com.
    ns4.he.net.
    ns5.he.net.
    ```

    #dns #authoritative #nameservers

  32. Good enough amount of name servers :P
    ```
    $ dig ns sahil.rocks +short
    ns2.afraid.org.
    marvin.sahilister.net.
    ns1.1984.is.
    ns0.1984.is.
    ns3.jing.rocks.
    colin.sahilister.net.
    puck.nether.net.
    ns2.albony.in.
    ns-global.kjsl.com.
    ns4.he.net.
    ns5.he.net.
    ```

    #dns #authoritative #nameservers

  33. Good enough amount of name servers :P
    ```
    $ dig ns sahil.rocks +short
    ns2.afraid.org.
    marvin.sahilister.net.
    ns1.1984.is.
    ns0.1984.is.
    ns3.jing.rocks.
    colin.sahilister.net.
    puck.nether.net.
    ns2.albony.in.
    ns-global.kjsl.com.
    ns4.he.net.
    ns5.he.net.
    ```

    #dns #authoritative #nameservers

  34. Good enough amount of name servers :P
    ```
    $ dig ns sahil.rocks +short
    ns2.afraid.org.
    marvin.sahilister.net.
    ns1.1984.is.
    ns0.1984.is.
    ns3.jing.rocks.
    colin.sahilister.net.
    puck.nether.net.
    ns2.albony.in.
    ns-global.kjsl.com.
    ns4.he.net.
    ns5.he.net.
    ```

    #dns #authoritative #nameservers

  35. Observing .ic TLD against authoritative nameservers serving samsung.com. No information of them anywhere.

    $ dig ns samsung.com +short
    auth04.sam.ic.
    auth02.nhn.ic.
    auth01.nhn.ic.
    dns-gi2.samsung.com.
    auth02.sam.ic.
    dnssm.samsung.com.
    dns-awskr1.samsung.com.
    dnssm2.samsung.com.
    dnsst.samsung.com.
    dnsst2.samsung.com.
    auth03.nhn.ic.
    auth04.nhn.ic.
    auth01.sam.ic.
    auth03.sam.ic.
    dns-gi1.samsung.com.

    Maybe some internal thingy? Thoughts?

    #DNS #Authoritative #Nameservers

  36. Observing .ic TLD against authoritative nameservers serving samsung.com. No information of them anywhere.

    $ dig ns samsung.com +short
    auth04.sam.ic.
    auth02.nhn.ic.
    auth01.nhn.ic.
    dns-gi2.samsung.com.
    auth02.sam.ic.
    dnssm.samsung.com.
    dns-awskr1.samsung.com.
    dnssm2.samsung.com.
    dnsst.samsung.com.
    dnsst2.samsung.com.
    auth03.nhn.ic.
    auth04.nhn.ic.
    auth01.sam.ic.
    auth03.sam.ic.
    dns-gi1.samsung.com.

    Maybe some internal thingy? Thoughts?

    #DNS #Authoritative #Nameservers

  37. Observing .ic TLD against authoritative nameservers serving samsung.com. No information of them anywhere.

    $ dig ns samsung.com +short
    auth04.sam.ic.
    auth02.nhn.ic.
    auth01.nhn.ic.
    dns-gi2.samsung.com.
    auth02.sam.ic.
    dnssm.samsung.com.
    dns-awskr1.samsung.com.
    dnssm2.samsung.com.
    dnsst.samsung.com.
    dnsst2.samsung.com.
    auth03.nhn.ic.
    auth04.nhn.ic.
    auth01.sam.ic.
    auth03.sam.ic.
    dns-gi1.samsung.com.

    Maybe some internal thingy? Thoughts?

    #DNS #Authoritative #Nameservers

  38. Observing .ic TLD against authoritative nameservers serving samsung.com. No information of them anywhere.

    $ dig ns samsung.com +short
    auth04.sam.ic.
    auth02.nhn.ic.
    auth01.nhn.ic.
    dns-gi2.samsung.com.
    auth02.sam.ic.
    dnssm.samsung.com.
    dns-awskr1.samsung.com.
    dnssm2.samsung.com.
    dnsst.samsung.com.
    dnsst2.samsung.com.
    auth03.nhn.ic.
    auth04.nhn.ic.
    auth01.sam.ic.
    auth03.sam.ic.
    dns-gi1.samsung.com.

    Maybe some internal thingy? Thoughts?

    #DNS #Authoritative #Nameservers

  39. How good (or a bad) idea is to run ones own authoritative nameservers?

    Any tips/tricks/suggestions or gotyas to remember?

    #dns #authoritative #nameservers

  40. How good (or a bad) idea is to run ones own authoritative nameservers?

    Any tips/tricks/suggestions or gotyas to remember?

    #dns #authoritative #nameservers

  41. How good (or a bad) idea is to run ones own authoritative nameservers?

    Any tips/tricks/suggestions or gotyas to remember?

    #dns #authoritative #nameservers

  42. How good (or a bad) idea is to run ones own authoritative nameservers?

    Any tips/tricks/suggestions or gotyas to remember?

    #dns #authoritative #nameservers

  43. How good (or a bad) idea is to run ones own authoritative nameservers?

    Any tips/tricks/suggestions or gotyas to remember?

    #dns #authoritative #nameservers

  44. To get away from CAs (#certificateAuthorities) i think web servers and sites ought have a list of other sites that they can vouch for, to bujild a Web Of Vouched Encryption And Names (WOVEAN), and then ppl can, as they type a name, see their WOVEAN address book in real time and see the sites that were used to vouch for the name and public key.

    So if my website links to a page then the public key of the site, in beech32 format (the format used by i2p) goes into a list for vouching. The more I use links to a site the stronger the "vouch" for that site.

    i suspect that every site will have on average 200-400 sites that they'd vouch for, with 150 of those being strong "vouches" but a fediverse server might end up with tens of thousands of weak "vouches". A fedizen who wants to visit postal.com might just be able to ask and fediserver for all names that start with "po".... if that would result in too big a list then the fediserver can refuse and the fedizen can ask for all results starting with "pos", an extra letter etc. this continues until a mapping of names to B32s can be provided.

    this sort of thing might work as part of an addon that i've been proposing to help fedizens crowd serve fediverse media over i2p. Media that they as INDIVIDUALS like and share, or (for improved #search) an INDIVIDUAL FEDIZEN might even share all posts that they can see, which use a #hashtag that they as an INDIVIDUAL have used. This proposed addon i have previously called #DCN (DeCentralized Network), which is ITSELF a tongue-in-cheek rebuttal of the oft-centralized #CDNs.

    i2p has a weird and annoying quirk that has made it technically totally possible for the #nameservers to claim a "subdomain" of a site, eg. betty in betty.postal.i2p belongs to a completely different entity to postal.i2p.... but for what i propose, if a browser WANTS to know what the B32 of betty.postal.i2p is then it would HAVE to ask postal.i2p. and it should be possible for a subdomain to have the same public key as the toplevel domain (currently i2p address books dont allow this, which is sort of dumb to me).

    really this system could work like the pet naming scheme from @cwebber et al

    does this sound compelling? really I don't think i'm outlining anything new here, ive just come up with an acronym, WOVEAN, which might help make the concept more palatable to the average non-techie,,,,

    Eg. "Is your site #wovean?"

    and i'm combining this with an addon proposal with overlapping functions.

    a negative is it may add to the amount of responsibility that webmasters/servers have, but not for i2p natives, as most people who share links in i2p will often share them alongside the b32 link. We WILL however want the webserver to be able to detect when it is sharing a WOVEAN link, so that it might AUTOMATICALLY(?) go into the sites address list? The browser addon would detect that a site is WOVEAN from info in the html head, and ask the viewer if they would like to "Fetch the WOVEAN addresses"?

    (If you dont interact I'll recommend to folks not to tag you, in subsequent resposes.)

    #encryption #naming #dns #mitm #infosec #sociology @gabriel @nimda @silverpill @fedilist @p @r @[email protected]

  45. Not combining #DNS and domain registration makes moving registrars a pretty pleasant experience: Throw in the #nameservers and #DNSSEC key and you're done.

    I really hate manually moving a bunch of records from one crappy zone editor to the another.

  46. I should've moved my #nameservers to #cloudflare sooner. The additional proxy setting is a nice feature to have.

  47. I should've moved my #nameservers to #cloudflare sooner. The additional proxy setting is a nice feature to have.

  48. 🤬 Why does #Linux (or rather #glibc) have a limit on 3 (in words: three) #DNS #nameservers‽ 🤌

    I want to have two IPv4 and two #IPv6 DNS servers listed as #nameserver in my /etc/resolv.conf. That's four DNS servers.

    Should I throw dices which one I list last and hence will get ignored and never used? (Yeah, the probably best workaround is to use #anycast. Cracking a nut with a sledgehammer…)

  49. 🤬 Why does #Linux (or rather #glibc) have a limit on 3 (in words: three) #DNS #nameservers‽ 🤌

    I want to have two IPv4 and two #IPv6 DNS servers listed as #nameserver in my /etc/resolv.conf. That's four DNS servers.

    Should I throw dices which one I list last and hence will get ignored and never used? (Yeah, the probably best workaround is to use #anycast. Cracking a nut with a sledgehammer…)