About DNS Institute

Who We Are

The DNS Institute was founded on a simple truth: DNS infrastructure is far more complex than most organizations realize, and that complexity hides critical misconfigurations, vulnerabilities, and compliance gaps. Even Fortune 500 companies, government agencies, and the world's largest financial institutions operate DNS systems with significant, discoverable problems.

Our principal expert brings 28 years of DNS professional experience — starting in 1999 as a DNS administrator for a recursive caching service supporting 500+ customer ISPs and 400+ authoritative DNS domains — combined with 18 years of rigorous, advanced QA testing experience in the DNS realm. This expertise includes teaching 20+ in-person DNSSEC and BIND courses (to clients including Rackspace, the U.S. Air Force, and VA hospitals), co-authoring DNS content for five published books, collaborating in modular DNS software design, managing incident response for 22+ DNS security vulnerabilities, and conducting extensive historical and real-time DNS analysis across millions of domains.

Our Research Program

The DNS Institute runs an ongoing, large-scale research program that continuously informs the evolution of the DNS Institute DNS Analyzer. Over the past several years, we have conducted deep analyses across Fortune 500 companies, top-100 global banking institutions, government domains across multiple nations, and all the top level domains. This research has uncovered novel vulnerability classes (dangling DNS with multiple variants), widespread DNSSEC deployment gaps, IPv6 configuration failures affecting over half of Fortune 500 companies, and recurring misconfigurations that plague even the largest, most security-conscious organizations.

Our analyses have generated over 50 million individual test results and identified hundreds of thousands of anomalies — from expired domains still being served, to out-of-sync TLD nameservers, to SPF records pointing to non-existent domains available for hijacking. See our full research archive for detailed findings and bibliographic references.

Why DNS Institute Exists

DNS appears straightforward but demands deep expertise to implement correctly. Standards evolve, implementations diverge, and the gap between "DNS works" and "DNS is correct" widens with each new RFC, government mandate, and security best practice. The DNS Institute DNS Analyzer was built to close that gap — to give organizations the visibility they need to move from overwhelming complexity to the confidence of clean, compliant DNS infrastructure.

We periodically expand our test suite to capture emerging DNS bugs, new RFC requirements, and evolving best practices. Your DNS security and reliability deserve expertise that matches the complexity you're navigating.

Ready to audit your DNS? Contact us for a free evaluation or demo.