Overview
deSEC is a free authoritative DNS host run by a non-profit organisation in Berlin. All of its software is open source, and every zone is signed with DNSSEC using elliptic-curve keys, with CDS/CDNSKEY support so registries can automate DS updates.
You can manage records in a web interface with live validation, or through a REST API with bulk operations, token permissions and bindings for Go, Python and JavaScript. A Terraform provider and Let's Encrypt integrations (certbot, acme.sh, lego) make it practical for DNS-01 certificate automation. deSEC also offers free dynDNS subdomains.
Because it is free and donation-funded, there is no SLA, no traffic steering (geo, failover, weighted) and the API has rate limits per domain. It is a DNS host only: no CDN, proxy or WAF.
deSEC is also part of the EU's DNS4EU consortium and has received funding from NLnet (NGI Assure), the ICANN Grant Program and RIPE NCC. Users with many domains, such as web hosts, are asked to contact support about their use case.
Pricing and plans
checked 28 Sept 2026Free tier · no card
Everything is free: managed domains and dynDNS, DNSSEC, API, anycast name servers; API rate limits apply.
| Plan | Price | What you get |
|---|---|---|
| Free | $0 | Managed domains, dynDNS, DNSSEC, REST API, 2FA |
What it does
- Always-on DNSSEC
- Every zone is signed automatically with modern elliptic-curve cryptography.
- Modern record types
- HTTPS/SVCB for apex aliasing, TLSA, OPENPGPKEY, SMIMEA, CDS and CDNSKEY.
- REST API
- Documented API with bulk operations, zonefile import/export and scoped tokens.
- Automation
- Terraform provider, language bindings and certbot, acme.sh and lego integrations.
- Anycast
- Global anycast frontend networks with full IPv6 support.
- Account security
- TOTP multi-factor authentication.
Strengths and limitations
Strengths
- Completely free, with no upsell.
- DNSSEC on by default for every zone.
- Open-source software and a non-profit operator in the EU.
- Good fit for DNS-01 certificate automation.
Limitations
- No SLA or paid support tier.
- No geo, latency, weighted or failover routing.
- API rate limits, such as 300 record changes per domain per day.
- Minimum TTLs are enforced; lower values need approval.
Who it suits
Good for
- Hobby and indie projects wanting free DNSSEC
- EU-based or privacy-focused teams
- Automated certificate issuance via DNS-01
Look elsewhere if
- Businesses needing an uptime SLA
- Apps needing traffic steering or failover
Alternatives to deSEC
| Tool | From | Free option | Stages |
|---|---|---|---|
| Amazon CloudFront CDN with bundled WAF and DNS plans | $15/mo | Free tier | |
| Bunny CDN Pay-as-you-go CDN with DNS and WAF | Usage-based | ||
| Cloudflare CDN, DNS, WAF and DDoS protection | $20/mo | Free tier | |
| ClouDNS Managed DNS with free and low-cost plans | $2.95/mo | Free tier | |
| DNSimple DNS hosting and domain management | $0.5/mo | ||
| easyDNS Managed anycast DNS and registrar | $20/yr |
Questions
Is deSEC really free?
Yes. deSEC is run by a non-profit and funded by grants and donations; there are no paid plans.
Does deSEC support DNSSEC?
Yes. Every zone hosted at deSEC is signed with DNSSEC, always.
Does deSEC have a Terraform provider?
Yes, deSEC lists Terraform providers alongside Go, Python and JavaScript bindings.
Does deSEC have API rate limits?
Yes, for example RRset changes are limited to 2 per second and 300 per day per domain; bulk requests help.
Sources read for this page