Comment on Recommendations to replace AWS DNS?

stratself@lemdro.id ⁨1⁩ ⁨week⁩ ago

Desec.io is a solid option - it allows for various types of records like TLSA and SRV. It can also generate scoped API tokens e.g. for “only TXT records of the _acme-challenge subdomain of example.com” to use in automated cert renewals, so pretty good for automation. It’s also a nonprofit.

I think selfhosting DNS is beneficial when you wanna control your own DNSSEC keys, but you’d need to account for high availability and safety. With that, you could do what’s called a “hidden primary + public secondary” setup to protect your master DNS data from the public prying. You can even use 3rd-party services like ns-global.zone as your secondaries for redundancy and to reduce load on your primary, too. I recommend Technitium and their guidance if you wanna get started

source
Sort:hotnewtop