{
  "slug": "hurricane-electric-free-dns",
  "category": "dns-hosting",
  "name": "Hurricane Electric Free DNS",
  "description": "Free authoritative DNS hosting from the US network operator Hurricane Electric, with forward and reverse zones, secondary DNS and dynamic DNS updates.",
  "website": "https://dns.he.net",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "F",
  "score": 25,
  "coverage": 100,
  "summary": "Hurricane Electric Free DNS scores 25 out of 100 (grade F) on the DNS hosting criteria. It meets 1 of 11 criteria: no ads or data sales. It partly meets no trackers or telemetry, transparency report and TLS configuration. It does not meet open source, independent audit, tells users about requests, security headers, DNSSEC, API access and two-factor login. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade D.",
  "url": "https://privacyratings.com/dns-hosting/hurricane-electric-free-dns/",
  "markdown": "https://privacyratings.com/dns-hosting/hurricane-electric-free-dns/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://he.net/privacy.html",
      "note": "No third-party trackers were found, but a first-party cookie records where visitors come from."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://he.net/privacy.html",
      "note": "Free service from a network operator funded by paid transit and hosting. The privacy policy says personal data is not disclosed to third parties."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://he.net/privacy.html",
      "note": "The privacy policy says user information is disclosed only to comply with law or valid legal process. No request counts are published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=dns.he.net&hideResults=on",
      "note": "Grade B"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "no",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=dns.he.net",
      "note": "Grade D (30/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "dnssec": {
      "title": "DNSSEC",
      "weight": 3,
      "answer": "no",
      "evidence": "https://dns.he.net",
      "note": "DNSSEC signing is not offered or listed among the service's features."
    },
    "api_access": {
      "title": "API access",
      "weight": 1,
      "answer": "no",
      "evidence": "https://dns.he.net",
      "note": "No API for managing zones. Only a dynamic DNS update endpoint for records marked as dynamic."
    },
    "two_factor": {
      "title": "Two-factor login",
      "weight": 2,
      "answer": "no",
      "evidence": "https://dns.he.net",
      "note": "No two-factor login is documented; the login form asks only for a username and password."
    }
  },
  "tests": {
    "ssllabs": "B",
    "observatory": "D",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T06:41:15.207Z"
  },
  "last_modified": "2026-10-01T06:56:31Z"
}