Skip to content
A chain of trust running from the signed root through a signed TLD and stopping at an unsigned second-level domain, with the counted figures beside each step

DNSSEC: Protecting Your Traffic From Forgery

The hard part of DNSSEC was finished years ago. Counted from the live root zone on 27 September 2026, 1,351 of 1,438 top level domains carry a DS record and every one of the 1,038 gTLDs is signed. Then it stops dead. A census of every gov.uk domain in the official register finds 39 signed out of 2,390 that still resolve, nine of them parish councils, while HMRC, the NHS, GCHQ and the National Cyber Security Centre are not among them. One certificate authority in nine has signed. So has one Linux distribution in three. windowsupdate.com has no DS at all. This is what a forged answer actually costs, what signing does about it, why the usual excuses do not survive contact with the numbers, and whether forty-two years after Mockapetris the real problem is that almost nobody understands what DNS actually promises.

27th September 2026 Β· 48 min Β· 10979 words Β· Damien Dye

Who Actually Controls DNS

The root of the internet is a 1.5 MB text file that one American company edits and signs. Who really controls DNS, what the 2016 IANA transition did and did not change, and the documented record of how ICANN has used that control.

25th August 2026 Β· 50 min Β· 10443 words Β· Damien Dye

What Happened at Nominet

The .uk registry is owned by its members, and in March 2021 they voted half the board out. What the estate actually looked like from inside, why running .uk alongside dozens of gTLDs shaped how it was run, and how a registry with no regulator ended up disciplined by the only people who could.

25th August 2026 Β· 29 min Β· 6147 words Β· Damien Dye