What Is NLnet Labs and What Software Does It Maintain?
NLnet Labs is a nonprofit foundation that builds open-source software for two core parts of internet infrastructure: DNS and routing. If you need a recursive resolver, an authoritative nameserver, DNSSEC signing, or RPKI tooling, its projects cover each of those roles as separate, focused tools rather than one bundled suite. The practical question is usually which project matches your role in the DNS or routing chain — that's what this breaks down.
Who NLnet Labs is
Stichting NLnet Labs is based at Science Park 400, Amsterdam, and describes itself as a non-profit Public Benefit Organisation (ANBI). Its stated focus is research and development around internet architecture, DNS, routing, stability, and security — writing code plus contributing to standards development and providing expert support.
Two things follow from that structure that matter when you're choosing software:
- The projects are open source, so you can inspect, deploy, and modify them without a commercial license gate.
- Support exists in tiers rather than being bundled into a product price: community support through a forum, and separately, professional support.
The DNS toolset
NLnet Labs maintains three DNS-side projects, and they occupy different positions in the resolution chain. Picking the wrong one is the most common confusion, so the distinction is worth stating plainly.
Unbound — recursive resolver
Unbound is a "lean and versatile recursive DNS resolver." A resolver is the component that takes a client's query and walks the DNS hierarchy to find the answer, then caches it. You run Unbound on the client-facing side — for example, on a network's internal resolver, a privacy-focused public resolver, or a local caching resolver on a server.
Choose Unbound when your job is answering queries on behalf of users or applications, not publishing your own zones.
NSD — authoritative nameserver
NSD is a "fast and robust authoritative DNS nameserver." An authoritative server holds the actual zone data for domains you own and answers queries about them. You run NSD when you are publishing DNS records for domains under your control.
Choose NSD when you need to serve your own zones to the rest of the internet.
Cascade — DNSSEC signing
Cascade is described as a "purpose-built DNSSEC signing solution." DNSSEC signing is a distinct job from serving: it's the process of cryptographically signing zone data so resolvers can verify it wasn't tampered with. Cascade addresses that signing workflow specifically, rather than being a general nameserver.
Choose Cascade when your concern is the signing and key-management side of DNSSEC, separate from the act of answering queries.
A quick way to hold the three apart:
| Project | Role in the DNS chain | Typical use |
|---|---|---|
| Unbound | Recursive resolver | Answering queries for clients, caching |
| NSD | Authoritative nameserver | Publishing your own zones |
| Cascade | DNSSEC signing | Signing zone data and managing keys |
A resolver and an authoritative server are not substitutes — many deployments run both, in different places. Signing sits alongside the authoritative side.
The routing and RPKI toolset
The other half of NLnet Labs' work is routing security, centered on RPKI (Resource Public Key Infrastructure), the system that lets network operators cryptographically validate which autonomous systems are allowed to originate which IP prefixes.
Routinator — RPKI relying party software
Routinator is a "lightweight RPKI Relying Party software." A relying party fetches and validates RPKI data so a router or routing system can use it to filter out invalid route announcements. Choose Routinator when you want to consume RPKI validation data to make routing decisions.
Krill — RPKI Certificate Authority
Krill is a "flexible and scalable RPKI Certificate Authority." A CA is on the publishing side of RPKI — it issues the certificates that resource holders use to make statements about their prefixes. Choose Krill when you are operating RPKI infrastructure (for example, as a Regional Internet Registry or a delegated CA), not merely consuming it.
Rotonda — BGP application platform
Rotonda is a "flexible BGP application platform." It's a framework for building BGP-speaking applications, which is a different kind of tool from the RPKI pair — it's about processing and acting on BGP data rather than validating RPKI objects.
The same publishing-versus-consuming split that applies to DNS applies here:
| Project | Side of RPKI/routing | Typical use |
|---|---|---|
| Routinator | Consuming | Validating RPKI data for route filtering |
| Krill | Publishing | Running an RPKI Certificate Authority |
| Rotonda | BGP processing | Building BGP-speaking applications |
How to decide which project you need
Work backward from your role rather than from the product names:
- You answer DNS queries for users or apps → Unbound.
- You publish DNS zones for domains you own → NSD.
- You need to sign those zones with DNSSEC → Cascade.
- You want to filter routes using RPKI validation → Routinator.
- You operate RPKI certificate issuance → Krill.
- You're building something that speaks BGP → Rotonda.
These are complementary, not competing. A single organization might run NSD for authoritative service, Cascade for signing, and Routinator for route validation — each solving a separate problem.
Support, documentation, and security reporting
NLnet Labs splits support into two channels:
- Community support — via the NLnet Labs community forum, which the site directs product support questions to.
- Professional support — a separate offering, with a published support policy, for organizations that need direct access to the people who build the software. The site frames this around avoiding downtime and ticket queues, but the specific terms and any costs are not stated on the page and should be confirmed directly.
For security, the site provides a dedicated security report submission path, and publishes software signing keys so you can verify the authenticity of releases. There's also a published LLM policy and a code of conduct for the organization.
One concrete example of why the security channel matters: the site notes that Unbound 1.26.1 addresses several security issues — one critical, plus high, medium, and low vulnerabilities. If you run Unbound, that's the kind of release you'd track and apply.
General contact is available at [email protected], but the site explicitly routes product support to the community forum rather than that address.
What this means in practice
NLnet Labs is best understood as a maintainer of discrete infrastructure components rather than a single product. The useful mental model is to identify your position in the DNS or routing chain first — resolver, authoritative server, signer, RPKI consumer, RPKI issuer, or BGP application — and then pick the matching project. Because the software is open source and the foundation is a nonprofit, the decision is driven by technical fit and support needs rather than licensing cost, with professional support available as a separate arrangement for those who need it.