Skip to content

Do you trust your registrar with DNS, or separate immediately?

Domain Names by marcus_qc 25 replies 2.8K views
8 #21
ronwit said:
$3 Vultr instance in Osaka

Vultr Osaka is good DC. I test there sometimes. But for DNS, single point of failure. Your 12 players maybe okay with downtime, but principle matters.

I run Pi-hole at home on Raspberry Pi 4, secondary to Vultr Singapore. Total cost $3/month. Local queries <1ms, fallback if ISP DNS dies. Benchmarked both. Pi-hole does ~25k qps with caching, enough for apartment.

fio, iperf, geekbench. results or gtfo.
1 #22

This. Separation doesn't have to be expensive or complex. I use Porkbun for domains, Cloudflare for DNS. Free tier. Took 30 minutes to switch first domain, then templated the rest. My "infrastructure" is a Ghost blog and a Nextcloud instance.

The peace of mind is disproportionate to the effort.

#23

Same here. Porkbun + Cloudflare. Used to use Namecheap's DNS because it was there. Realized I couldn't set a CAA record without upgrading to some paid tier. Moved that afternoon.

Free Cloudflare has CAA, DNSSEC, 300s TTL minimum. More than I need.

#24
Pure59 said:
Couldn't set a CAA record without upgrading

This is exactly the hidden cost of bundled DNS. They nickel-and-dime you for features that are table stakes elsewhere. "Oh you want DNSSEC? That's enterprise." Meanwhile Cloudflare gives it away to sell you other things later.

My registrar wanted $15/year for "advanced DNS" including ALIAS records. Vultr includes ALIAS/ANAME on every zone for the $3 instance price: https://www.vultr.com/pricing/

42U and still growing
#25

To bring this back to the actual security question: the original concern was correlation risk. Having registrar and DNS at one company means one support ticket, one legal order, one compromised account can change both ownership and resolution path.

Separate doesn't eliminate risk. If your registrar account is compromised, attacker can still change NS records to evil DNS. But now they need to also compromise the DNS provider to maintain control, or rely on TTL expiration. Adds steps. Adds detection time.

RPKI + DNSSEC with proper DS at registrar closes the loop even with separate providers. Do both.

iBGP, eBGP, don't care, just peer
#26

Did anyone mention that some registrars lock you in by not supporting custom nameservers on cheaper tiers? I had to upgrade to "Pro" just to point NS records to Cloudflare. The DNS separation had a $25/year tax attached.

Still did it. But annoyed.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft