All my domains are under control of stargrave.org's nameservers. DNSSEC is global-scale PKI, with single trust anchor controlled by USA/NATO. That is why, my nameservers use DNSCurve technology and DANE. All X.509 certificates are also signed by my own CA. => https://dnscurve.io/faq/differences-between-dnscurve-and-dnssec.html => DNSCurve => ca.stargrave.org CA Most of my domains has y. prefix, leading to Yggdrasil accessible address. => Yggdrasil