{
  "slug": "desec",
  "category": "dns-hosting",
  "name": "deSEC",
  "description": "Free authoritative DNS hosting from the Berlin non-profit deSEC e.V., with automatic DNSSEC signing, a full REST API and open-source software.",
  "website": "https://desec.io",
  "source": "https://github.com/desec-io/desec-stack",
  "license": "MIT",
  "platforms": [],
  "jurisdiction": {
    "code": "DE",
    "name": "Germany",
    "eyes": "Fourteen Eyes",
    "eu": true,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "B",
  "score": 77,
  "coverage": 100,
  "summary": "deSEC scores 77 out of 100 (grade B) on the DNS hosting criteria. It meets 8 of 11 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, security headers, DNSSEC, API access and two-factor login. It does not meet independent audit, transparency report and tells users about requests. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
  "url": "https://privacyratings.com/dns-hosting/desec/",
  "markdown": "https://privacyratings.com/dns-hosting/desec/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/desec-io/desec-stack/blob/main/LICENSE",
      "note": "MIT."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://desec.io/privacy-policy",
      "note": "The privacy policy states no tracking, behavioral analytics or externally hosted dependencies are used."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://desec.io/about",
      "note": "Run by a non-profit association funded by donations and grants. No ads."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No transparency report or government request policy is published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=desec.io&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=desec.io",
      "note": "Grade A+ (105/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "dnssec": {
      "title": "DNSSEC",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://desec.io/",
      "note": "Every hosted zone is signed with DNSSEC automatically. The DS record is added at the registrar."
    },
    "api_access": {
      "title": "API access",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://desec.readthedocs.io/en/latest/",
      "note": "All records are managed through the REST API, which every free account can use."
    },
    "two_factor": {
      "title": "Two-factor login",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://desec.io/",
      "note": "TOTP authenticator apps are supported for login."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "A+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:01:24.266Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}