How this site is secured

dnssec.me is served over HTTPS with HSTS, a strict Content-Security-Policy and modern cross-origin isolation headers. Analytics are consent-gated — nothing loads from Google Tag Manager unless you choose "Accept all" on the cookie banner. There is no web contact form and no account system, so there is no enquiry database to breach.

Reporting a vulnerability

If you believe you have found a security vulnerability in this website, email [email protected] with:

  • a description of the issue and where you found it;
  • the steps needed to reproduce it; and
  • the potential impact as you see it.

Please give us a reasonable chance to investigate and fix the issue before disclosing it publicly. We will acknowledge your report, keep you updated, and credit you if you would like once it is resolved.

Please do not

  • Access, modify or delete data that is not yours, or degrade the service for others — no denial-of-service or spam testing.
  • Test DNS infrastructure that does not belong to us. The domains used as examples in our guides belong to other people.
  • Use social engineering or physical attacks.

Safe harbor

If you make a good-faith effort to follow this policy, we will treat your research as authorised and will not pursue or support legal action against you for it. If you are unsure whether an action is acceptable, ask first at [email protected].

A machine-readable version of this contact is published at /.well-known/security.txt.

Related: Privacy Policy · Contact