Releases: jameshoulder/dnsdaddy
Release list
DNS Daddy v0.3.0-alpha.1 — Evidence, Decisions & External Intelligence
DNS Daddy v0.3.0-alpha.1 — Evidence, Decisions & External Intelligence
This is an early v0.3 development release of DNS Daddy.
Since v0.1.0, the project has moved beyond basic protective DNS controls toward a more explainable security platform: external threat-intelligence integrations, a common evidence model and persistent decision records that begin to answer a very important question:
Why was this domain blocked?
This remains an experimental pre-release and should not be treated as a finished v0.3 release.
Highlights
Bring your own threat intelligence
DNS Daddy can now integrate external reputation and enrichment services through Protect → External APIs.
Built-in support includes:
- VirusTotal
- Google Safe Browsing
- Custom HTTP/JSON providers
- Provider connection testing
- Provider health monitoring
- Rate limiting and circuit breaking
- Reputation caching
External integrations are disabled by default.
Operators explicitly choose whether a provider can participate in DNS decisions.
Secure credential handling
Provider credentials are encrypted at rest using AES-256-GCM.
Credentials are write-only through the management API and are not returned in API responses after configuration.
DNS Daddy displays only whether a credential is configured and limited identifying information such as its final characters.
Reputation modes
External intelligence can operate in three modes:
off— providers are not consultedcache_only— only locally cached reputation is usedblocking— DNS Daddy may briefly wait for a provider response within a bounded timeout
The configuration file establishes the maximum permitted mode, while the dashboard may lower it during operation.
A provider failure or timeout is treated as unknown, not malicious.
Evidence model
v0.3 begins introducing a common representation for security evidence.
Previously, blocklists, behavioural findings and external reputation providers all represented evidence differently.
DNS Daddy now has a shared evidence model that records:
- what was observed
- which source reported it
- when it was observed
- the claim being made
- confidence
- expiry
- supporting detail
Corroboration is represented through named independent sources rather than by generating an artificial combined confidence score.
Decision records — "Why was this blocked?"
DNS Daddy can now persist the reasoning behind enforced DNS decisions.
A recorded decision links:
DNS event → evidence → decision → explanation
The explanation is stored at the time the decision occurs rather than reconstructed later from whatever threat intelligence happens to exist at the time somebody investigates it.
This means a feed changing tomorrow does not silently rewrite the explanation for a block that happened today.
Decision recording is intentionally off by default.
When enabled, records are written asynchronously so database latency is not placed in front of DNS responses.
Management API
New API capabilities include endpoints for:
- external intelligence provider management
- provider health and connection testing
- evidence retrieval
- decision retrieval
- recorded decision explanations
The OpenAPI specification and contract tests have been extended alongside the implementation.
Deployment and reliability
This release also includes additional deployment hardening discovered through real VPS testing.
Notable fixes include:
- improved Caddy/ACME diagnostics
- safer HTTPS rollback behaviour
- container-aware exposure diagnostics
- installer improvements
- improved service and Caddy permission checks
- health checks after rollback
- safer handling of existing deployments
- a pipefail race that could cause
--upgradeto incorrectly reject DNS Daddy's own port 53
UI and documentation
The project README and visual presentation have also been refreshed with:
- updated DNS Daddy branding
- dashboard screenshots
- clearer product positioning
- improved assurance messaging
- stronger distinction between protection, observation, warnings and security findings
Security posture
DNS Daddy remains an experimental open-source security project.
The project has extensive automated tests, security scanning, static analysis and real-world deployment testing, but it has not undergone an independent professional security audit.
External intelligence also introduces an important privacy consideration:
when a provider is actively queried, the domain being resolved may be sent to that third party.
This behaviour is opt-in and is documented in the provider configuration.
Known limitations
This is an alpha milestone, not the completed v0.3 release.
In particular:
- the planned v0.3 assurance phase is not yet complete
- decision recording is disabled by default
- allow-list hits are not currently recorded as decisions
- only evidence directly responsible for a decision is currently cited
- behavioural detectors remain alerting mechanisms rather than automatic enforcement
- external provider adapters should be tested by operators against their chosen live services
- DNSSEC is not locally validated
- behavioural detection does not yet have a published measured real-world false-positive rate
- no independent professional security review has taken place
What's next
The next v0.3 work focuses on assurance: documenting security claims and their evidence, strengthening false-positive testing methodology and making the boundaries of what DNS Daddy can and cannot currently prove clearer.
Feedback, testing, code review and responsible security research are very welcome.
Full comparison: v0.1.0...v0.3.0-alpha.1
DNS Daddy v0.1.0 — Initial Public Release
DNS Daddy v0.1.0 — Initial Public Release
This is the first versioned public release of DNS Daddy.
DNS Daddy is an open-source, self-hosted protective DNS project exploring how DNS security controls can be made more accessible, understandable and practical for smaller organisations, homelabs and security learners.
Highlights
- Protective DNS resolver functionality
- DNS access-control protections
- Open-resolver safeguards
- Web-based management interface
- Docker-based deployment
- LAN and homelab deployment support
- Secure VPS deployment workflow
- Caddy HTTPS support
- Deployment diagnostics and
doctortooling - Security-focused configuration defaults
- Automated testing and regression coverage
Deployment improvements
Recent work has significantly improved the real-world VPS deployment experience, including fixes identified through testing DNS Daddy on an actual public VPS.
This includes improvements around:
- Caddy HTTPS deployment
- ACME certificate diagnostics
- Caddy configuration permissions
- rollback behaviour
- container health checks
- management interface exposure detection
- deployment diagnostics
Security
DNS Daddy remains an experimental open-source security project.
Although the project has undergone automated security testing, code review, vulnerability scanning and real-world deployment testing, it has not yet undergone an independent professional security audit.
It should therefore not currently be considered a drop-in replacement for mature commercial protective DNS platforms in critical production environments.
Security testing, peer review, feedback and responsible disclosure are very welcome.
Project status
v0.1.0 establishes the first versioned baseline of DNS Daddy.
Development will continue, with planned work including additional threat-intelligence integrations, investigation capabilities, usability improvements and further security hardening.
Thank you to everyone following, testing and providing feedback on the project.