---
title: Role of deSEC in the DNS4EU project
description: DeSEC and their role in the project
image: https://joindns4.eu/hubfs/Desec%20blog%20post.png
---

[Skip to content](https://joindns4.eu/learn/role-of-desec-in-dns4eu#main)

[![DNS4EU](https://joindns4.eu/hubfs/dns4eu/img/dns4eu-black.svg) Powered by ![Whalebone](https://joindns4.eu/hubfs/dns4eu/img/whalebone-black.webp)](https://joindns4.eu/)

[Public service](https://joindns4.eu/for-public) [Governments](https://joindns4.eu/for-governments) [Public institutions](https://joindns4.eu/for-public-institutions) [Private companies](https://joindns4.eu/for-private-companies)

[Contact](https://joindns4.eu/contact)

[Learn](https://joindns4.eu/learn)

# Role of deSEC in the DNS4EU project

Security from the Start

In the web, HTTP traffic (such as a search query) is usually protected in a way so that clients (browsers) can verify, using cryptographic techniques, that the traffic was not manipulated on the way from the web server. This type of protection is not always there when it comes to DNS traffic: DNS queries and responses are mostly transmitted without cryptographic protection, and are subject to certain kinds of attacks.

#### ![Desec blog post](https://joindns4.eu/hs-fs/hubfs/Desec%20blog%20post.png?width=427&height=268&name=Desec%20blog%20post.png)

Given that DNS queries and responses happen as the very first step of a connection (even before HTTPS!), DNS-based attacks have the potential to undermine the reliability of connections as a whole. When the Internet was conceived, this was not much of a problem, as it was used for academic purposes and abuse was low. The absence of security in the early design of the Internet also allowed for conceptual simplicity, which made it easily extensible and has contributed to the Internet's tremendous success. But today, it's time to fix those holes that were left open in the past.

Securing the DNS

Developments from recent years have enabled DNS providers (who are the source of DNS responses) to secure their DNS responses with digital signatures, using a technology called DNSSEC. It's a complex mechanism, and while its operation can be automated almost entirely, there are a number of choices in how exactly to run it. This reflects DNS operations in general, where there are a lot of knobs to configure behaviour for a number of edge cases, some of which are mainly performance-related while others have implications for security and privacy.

Role of deSEC in DNS4EU

deSEC's mission is to make the Internet a more trustworthy place. We focus on this goal using technical means, as people and their applications need a solid underlying technical foundation in order to build "trustworthy real-world things" on top. In particular, we work to advance the state of DNS security.

That's why deSEC participates in DNS4EU. As a not-for-profit player from the Internet security community, we'd like to help develop a solid security posture, advise on privacy and security issues related to DNSSEC and beyond, and enable a healthy culture of considering security in the European DNS Resolver from the start.

*This blog post was written by deSEC, a member of DNS4EU consortium.*

Download

## Where should we send it?

Company website

First name\*

Last name\*

Work email\*

Organization name\*

Type of organization\* Please choose Education Healthcare Municipality Government Ministry or national authority Other public body Private company

How did you hear about us Please choose Search engine ChatGPT or another AI Social media An online ad A colleague or peer An event or conference Press or an article The DNS4EU newsletter A Whalebone employee Other

Get the document

To respond to your request, we need to process the personal data you provided.

[Learn more about our privacy policy](https://joindns4.eu/privacy-policy)\*

![DNS4EU](https://joindns4.eu/hubfs/dns4eu/img/dns4eu-white.svg)

European protective DNS resolution, operated on EU infrastructure under EU rules.

 Powered by ![Whalebone](https://joindns4.eu/hubfs/dns4eu/img/whalebone-color.webp)

- [LinkedIn](https://www.linkedin.com/showcase/dns4eu/)
- [X](https://www.twitter.com/DNS4EU)
- [YouTube](https://www.youtube.com/@Whaleboneio)
- [Facebook](https://www.facebook.com/dns4eu)

## For organizations

- [Governments](https://joindns4.eu/for-governments)
- [Public institutions](https://joindns4.eu/for-public-institutions)
- [Private companies](https://joindns4.eu/for-private-companies)

## Free public service

- [Set it up](https://joindns4.eu/for-public#setup)
- [Choose a variant](https://joindns4.eu/for-public#choose)
- [Report a blocked site](https://joindns4.eu/for-public#report-a-site)

## About DNS4EU

- [About the project](https://joindns4.eu/about)
- [Learn](https://joindns4.eu/learn)
- [Events](https://joindns4.eu/events)
- [Newsletter](https://joindns4.eu/#newsletter)
- [Contact](https://joindns4.eu/contact)
- [Whalebone](https://www.whalebone.io/immunity)

Project number: 101095329 21-EU-DIG-EU-DNS  
 Project name: DNS4EU and European DNS Shield.  
 This project was co-funded by the European Union from 2023-2025

© 2026 DNS4EU. Operated by Whalebone, s.r.o., Jezuitská 14/13, 602 00 Brno, Czech Republic, Company ID: 05120403, Vat No.: CZ05120403, Email: [info@whalebone.io](mailto:info@whalebone.io)

Registered in the Commercial Register under File No. C 93547 maintained by the Regional Court in Brno

[Legal information and compliance](https://joindns4.eu/legal-information-and-compliance) [Privacy policy](https://joindns4.eu/privacy-policy)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "DNS4EU",
    "url" : "https://joindns4.eu/learn/author/dns4eu"
  },
  "dateModified" : "2024-06-04T08:34:32.087Z",
  "datePublished" : "2024-05-27T09:16:06.000Z",
  "headline" : "Role of deSEC in the DNS4EU project",
  "image" : [ "https://joindns4.eu/hubfs/Desec%20blog%20post.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://joindns4.eu/learn/role-of-desec-in-dns4eu",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject"
    }
  }
}
```