Stichting NLnet Labs (NLnet Labs for short) is a not-for-profit foundation founded in 1999 in the Netherlands. Its statutes define its objectives: to develop Open Source software and open standards for the benefit of the Internet.
NLnet Labs' mission is:
To provide globally recognized innovations and expertise for those technologies that turn a network of networks into an Open Internet for All.
» Read more about Labs.

NLnet Labs is a charitable foundation (ANBI) and our main source of income is a subsidy from SIDN and a subsidy from the NLnet Foundation. As we're moving forward and need to ensure our continuity, we welcome your support! In order to develop a sustainable income, we invite you to consider our Support and SLA services, provided by Open Netlabs BV being a 100% subsidiary of NLnet Labs.
» Read more about our funding.

Software updates

Unbound 1.5.10 released

Tue, 27 Sep 2016
In this release there is a fix for long downtime after connectivity loss, which was a longstanding unsolved issue. Features for tcp, TCP Fast Open and timeout pressure to close connections when the tcp connections are getting full. Option to use ipv6 /64 for extra entropy. More bug fixes.
Unbound website. Direct Download. Changes.

NSD 4.1.13 released

Fri, 27 Sep 2016
Some features, such as multi master check option that does not upgrade from the first master that answers, but picks the best one. Additional section handling for type SRV. And bug fixes.
NSD project page. Direct Download.

NSD 4.1.12 released

Fri, 02 Sep 2016
Fix malformed edns query assertion failure, reported by Michal Kepien (NASK).
NSD project page. Direct Download.

NSD 3.2.22 released

Tue, 14 Jun 2016
Bug fixes accrued before end of support. Note that 3.2.x has end-of-support.
NSD project page. Direct Download.

Unbound 1.5.9 released

Thu, 09 Jun 2016
New IPv6 address for one of the root servers in the default root server configuration. And a number of bug fixes, for CD flags to forwarders, for 0x20 compatibility, for qname-minimisation with DNSSEC.
Unbound website. Direct Download. Changes.

getdns 0.9 released

Thu, 31 Dec 2015
Special New Year's Eve release of getdns. This release brings the implementation on par with the December 2015 version of the specification.
Announcement. Direct Download. API specification.

DNSSEC trigger 0.13 for OS X 10.11 released

Thu, 8 Dec 2015
Update and correct install on Mac OS X 10.11 (El Capitan) systems.
DNSSEC trigger project page. Direct Download.

Net::DNS::SEC 1.01 released

Mon, 3 Aug 2015
Crypto funcs for Net::DNS 1.01 DNSSEC RR's
Net::DNS::SEC 2.01 release announcement. Project website. Direct Download. Changes.

Net::DNS 1.01 released

Mon, 6 Jul 2015
First major release, DNSSEC RR's integrated
Net::DNS 2.01 release announcement. Project website. Direct Download. Changes.


NLnet Labs Annual Report 2014

Wed, 30 June 2015
We are happy to present NLnet Labs Annual report 2014. In it we present an overview of Labs' various activities and describe their impact.
Annual Report 2014 (PDF).

BGP Route Leaks Analysis

Fri, 6 Mar 2015
A route leak is a violation of the policies between the networks involved. In this project, we obtain routing information from differecent sources and make inferences to detect possible route leaks. These potential route leaks have been further investigated on their duration, the type of violation, and the type and origin of network that caused the leak-detection.
MSc. report (PDF).

BGP Evolution Analysis

Thu, 31 Jul 2014
The Internet has been growing rapidly for many years. A logical consequence of the growth trend is the increase in effort to discover reachability and routing information of all the networks. The project investigates the different components which together form the actual update message signal and tries to find a reason behind the growth factor.
MSc. report (PDF).

Measuring the Deployment of DNSSEC over the Internet

Thu, 2 Jul 2014
The deployment of DNSSEC is measured with the RIPE Atlas infrastructure. The results provide new insight on the distribution of DNSSEC support among resolvers, and notably show that around 90% of resolvers are DNSSEC-aware, and about 30% validate answers.
MSc. report (PDF).

Open Data Analysis to Retrieve Sensitive Information Regarding National-Centric Critical Infrastructures

Mon, 3 Feb 2014
Open Data repositories store a variety of information from country governments and private sectors. A concern is that with publishing data, sensitive information can be obtained by visual analytic techniques. The report shows that it is possible to retrieve precise locations where critical infrastructures overlap.
MSc. report (PDF).


CDAR Root Stability Study commissioned by ICANN

Thu, 3 Dec 2015
NLnet Labs, SIDN and TNO have been commissioned by ICANN to examine the impact of the new gTLD programme on the root server system.
Press release.

Akkerhuis selected for DNS Root Zone KSK design team

Thu, 5 Feb 2015
Jaap Akkerhuis from NLnet Labs has been selected for the DNS Root Zone KSK rollover plan design team.
ICANN Announcements.

Recent blog posts

Tue, 16 Aug 2016 by yuri
“I Can’t Believe It’s Not DNS!” is an authoritative DNS server on ESP8266 written in MicroPython. It has the following anti-features: No storage of zone files, AXFR each boot. DNSSEC filtering. TSIG-less AXFR support! Notify ‘handling’. Highly optimized: no sanity checks. Jumping on the Bandwagon The Espressif ESP8266 is one of the favorite microcontrollers of IoT-Hipsters for some [...]
Thu, 29 Oct 2015 by yuri
Erratum: Unfortunately it appears that this method does not work for OpenDNSSEC 1.4.x. It still works for 1.3.x, specifically 1.3.18 is tested (thanks Michał Kępień!). The current version of OpenDNSSEC is unable to perform an algorithm rollover. Blindly changing the KSK and ZSK algorithm in the kasp.xml will result in a bogus zone. The only option ...
Fri, 19 Sep 2014 by wouter
NSD 4.1: zonefile-mode and fork fix Use zone files and not nsd.db NSD 4.1 has been released and it contains a new feature where NSD does not use the nsd.db file, but uses the zonefiles directly.  The feature can be turned on by configuring one line in nsd.conf, it can also be turned off by ...
Mon, 15 Sep 2014 by benno
NLnet Labs announces that it will take full responsibility for continuing the activities of both the OpenDNSSEC softwareproject as well as the support activities of the Swedish OpenDNSSEC AB. OpenDNSSEC was created as an open source turn-key solution for DNSSEC, managing the security of domain names on the Internet. The project drives adoption of Domain ...

Tue Aug 16 2016

© Stichting NLnet Labs

Science Park 400, 1098 XH Amsterdam, The Netherlands

labs@nlnetlabs.nl, subsidised by NLnet and SIDN.