The Distributed DNS for the Open Internet
Eliminate downtime and centralized vulnerabilities with our Distributed Domain Name Resolution System, a resilient infrastructure built for reliable, efficient, and tamper-proof DNS. A zero-cost ecosystem for approved participants, powered by fully open code and guided by collective community leadership.
How distributed resolution works
DDNRS replaces the traditional centralized DNS hierarchy with a peer-validated, distributed resolution protocol that is resilient by design at every layer.
Query Initiation
A resolution request is issued from the client. The DDNRS resolver selects the optimal entry node from the regional registry based on current latency and availability scores.
Peer Propagation
The query propagates across the distributed node mesh. Each peer maintains a partial copy of the global zone table, using Merkle-verified consensus to agree on authoritative records.
Cryptographic Verification
Records are signed with the zone owner's Ed25519 key. Clients verify every signature before accepting results, eliminating cache poisoning and DNS spoofing at the protocol level.
Verified Response Delivery
The verified result is returned with full audit metadata — node path, verification hash, and TTL. Records are cached locally with tamper-evident signatures for all subsequent lookups.
Built for reliability at global scale
Decentralize your domain resolution. A high-performance DNS platform engineered for transparency and resilience, cutting the cord from centralized gatekeepers.
Decentralized Zone Authority
Zone records are anchored to cryptographic key pairs, not registrar accounts. You control your namespace directly — no central authority can suspend or redirect your domains without your private key.
Sub-20ms Global Resolution
With nodes across 3600 or more geographic regions, DDNRS routes each query to the nearest peer cluster, achieving resolution times consistently comparable to commercial managed DNS at zero cost.
End-to-End Record Signing
All zone records are signed with Ed25519 keys at publish time and verified client-side on every resolution — a strict superset of DNSSEC with no additional configuration required.
Automatic Failover and Healing
The node mesh continuously monitors peer health. On failure, queries are rerouted in under 200 ms. Zone data is always replicated across at least five independent nodes simultaneously.
DoH and DoT Transport Support
All DDNRS endpoints natively support DNS-over-HTTPS and DNS-over-TLS transports, protecting every resolution request from network-level surveillance and passive eavesdropping.
Developer-First API and SDKs
Manage zones, publish records, monitor resolution health, and query audit logs via a clean REST API with open source SDKs for Node.js, Python, Go, and Rust under the MIT License.
System architecture overview
DoH / DoT / DDNRS-RPC
Peer Mesh Routing
Merkle Zone Validation
Distributed Zone Store
A layered, peer-validated stack
DDNRS is designed with strict layer separation to allow independent upgrades and auditing of each subsystem. The protocol is fully open and specified in the DDNRS RFC series.
- Application layer supports standard DNS wire format for drop-in compatibility
- Peer mesh uses a modified Kademlia DHT for robust node discovery and routing
- Merkle zone trees enable compact proofs of record inclusion and exclusion
- Storage layer supports pluggable backends including LevelDB, LMDB, and RocksDB
- All inter-node communication is encrypted with mutual TLS 1.3
- Zone metadata anchored to a public, tamper-evident transparency log
Designed for these real-world scenarios
DDNRS serves organizations and individuals that need resilient, sovereign DNS infrastructure beyond what registrar-tied or commercial providers can reliably offer.
Resilient Infrastructure for OSS Communities
Open source projects often lack the budget for managed DNS with SLA guarantees. DDNRS provides enterprise-grade availability at zero cost, sustained by a nonprofit community of contributors.
Isolated Namespaces for Dev and Staging
Spin up isolated DNS namespaces for feature branches, staging environments, and local development clusters — with automatic teardown policies and full API control over the namespace lifecycle.
Publishing Without a Single Point of Failure
Applications in restricted environments need DNS that cannot be silenced by targeting one registrar. DDNRS has no central chokepoint that an adversary can seize, compel, or take offline.
DNS Protocol and Security Research
Universities and security researchers gain access to a live, open, fully instrumented resolution network with complete protocol introspection capabilities built into the node software.
Human-Readable Names for Decentralized Apps
Decentralized applications need naming that matches their architecture. DDNRS resolves both traditional DNS records and custom TLD namespaces controlled by on-chain key pairs.
DNS for Private Infrastructure and IoT Fleets
Deploy DDNRS nodes within private infrastructure for naming in mesh networks, IoT device fleets, and air-gapped environments, with an optional sync bridge to the public overlay.
Apply for DDNRS access
All access is granted through a reviewed application. We do not sell plans or subscriptions — this protects network integrity and ensures fair access for every participant.
Frequently asked questions
More questions? Reach the community via the public mailing list.