Position
AI-assisted, transparently built, test-backed — and unaudited.
DNS Daddy is built with AI assistance. That is disclosed rather than hidden.
The useful question is not “Was AI used?” The useful question is “What evidence exists for this claim?”
“Implemented” means the feature exists and its tests pass. It does not mean the feature has survived adversarial review by anyone qualified. Nothing on this page has been independently audited.
Vocabulary
What each label on this page means.
- IMPLEMENTEDRe-checked automatically on every change.
- TESTEDExercised by a tool or person at a stated point in time.
- EXPERIMENTALWorking, but not calibrated sufficiently against real production traffic.
- NOT INDEPENDENTLY AUDITEDNo independent evidence currently supports the claim.
Automated
Re-run on every change in continuous integration.
- Build, vet, unit and integration testsIMPLEMENTED
- Race detectorIMPLEMENTED
- staticcheckIMPLEMENTED
- gosecIMPLEMENTED
- govulncheckIMPLEMENTED
- CodeQL and SemgrepIMPLEMENTED
- Container and filesystem scanIMPLEMENTED
- End-to-end resolver testIMPLEMENTED
Testing
Carried out at a stated point in time.
- Vulnerability scanningTESTED
Run at a point in time, not continuously.
- Behavioural detection accuracyEXPERIMENTAL
Not calibrated against production traffic.
Daddybound
Experimental DNSSEC validation engine
Daddybound is an isolated experimental DNSSEC validation engine being developed from the standards and tested against established validators.
Not connected to the live DNS resolution path
It answers no queries, enforces no policy and cannot be pointed at the internet or at a running deployment. A test asserts that no package on the query path can reach it.
- Positive chain validationImplemented · experimental
Walks a signed chain against an in-memory hierarchy in the laboratory only.
- Differential test laboratoryImplemented
Compared against two independent reference validators across eighteen laboratory scenarios.
- Negative validation (NSEC / NSEC3)Planned
No authenticated NXDOMAIN or NODATA yet; the Insecure state is reported as Indeterminate.
- Resolver integrationPlanned
None today, by design and enforced by an import test.
DNS Daddy does not perform local DNSSEC validation on the resolution path. The DNSSEC status shown against a query is the verdict reported by a validating upstream resolver.
Limitations
- No independent professional security review.
- Scanners are not proof.
- Behavioural detection is experimental.
- Self-hosting means deployment security is partly the operator's responsibility.
This demo reproduces the Assurance page so its wording can be read before installing. The authoritative statement of what is implemented, experimental or planned lives in docs/capabilities.md in the DNS Daddy repository.