pkg.sopackage field notes

brew / rank 875

Install ldns with Homebrew

DNS library written in C. Version 1.9.2 via Homebrew; verified 2026-06-22.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install ldns

provider-native install command

overview

Package summary

DNS library written in C

Commands and aliases

  • drill
  • ldns-chaos
  • ldns-compare-zones
  • ldns-config
  • ldns-dane
  • ldns-dpa
  • ldns-gen-zone
  • ldns-key2ds
  • ldns-keyfetcher
  • ldns-keygen
  • ldns-mx
  • ldns-notify
  • ldns-nsec3-hash
  • ldns-read-zone
  • ldns-resolver
  • ldns-revoke
  • ldns-rrsig
  • ldns-signzone
  • ldns-test-edns
  • ldns-testns
  • ldns-update
  • ldns-verify-zone
  • ldns-version
  • ldns-walk
  • ldns-zcat
  • ldns-zsplit
  • ldnsd

history

Project history and usage

ldns is NLnet Labs' C library for DNS and DNSSEC programming, accompanied by command-line tools such as drill and many DNSSEC utilities. NLnet Labs describes its goal as simplifying DNS programming in C while supporting low-level DNS and DNSSEC operations.

Project history

The project appeared in 2005 during the period when DNSSEC tooling was maturing. Its changelog records a first usable 0.50 release in May 2005, an online repository in June 2005, and a 1.0.0 release in October 2005 that added drill to ldns, zonefile parsing, an experimental signer, and a BSD license.

ldns evolved into both a library and a toolbox. Drill, originally important enough that documentation says part of ldns was derived from it, became included in ldns releases from version 1.0.0 onward. The examples directory grew into a collection of practical DNSSEC and zone tools, including signers, validators, key helpers, and packet utilities.

Later releases tracked DNS standards work. The changelog records additions such as NSEC3-related utilities, DANE support in 2012, SVCB/HTTPS support in the 1.8 series, and newer resource-record handling in the 1.9 series. NLnet Labs stated that ldns entered maintenance mode in 2020, with ongoing fixes and occasional experimental use rather than broad feature expansion.

Adoption history

ldns gained adoption among DNS implementers, operators, and package maintainers because it offered a C API plus ready-to-run diagnostic tools. Distribution packaging reflects that split: some systems package the tools as ldnsutils or drill while others package the library and tools together.

The project also became a bridge between DNS research and production packaging. NLnet Labs explicitly notes use for proof-of-concept work around Internet Drafts, while the maintained command-line tools made it useful for operators who needed DNSSEC-aware zone inspection, signing, verification, and query tracing.

How it is used

Developers use the library through ldns structures such as resource records, packets, zones, and resolvers. Command-line users most often encounter drill as a dig-like DNS inspection tool and the ldns-* utilities for DNSSEC key, zone, signing, walking, comparison, and verification workflows.

The documentation stresses OpenSSL-backed cryptographic features, optional builds without OpenSSL, IPv4/IPv6 support, TSIG, DNSSEC signing and verification, manual pages, and API documentation.

Why package nerds care

ldns matters to package nerds because it is a compact DNSSEC lab in package form: a C library, a resolver/query tool, many small executables, optional crypto features, Python bindings, and a long changelog tied to RFC and draft support. It is also a good example of an upstream declaring a maintenance-mode successor path while keeping old Unix packages useful.

NLnet Labs names the Rust domain library as the natural successor to the ldns library, dnst as drop-in replacements for common example utilities, and dnsi as a reimagined DNS inspection tool. That makes ldns a legacy-but-alive package with clear lineage into newer NLnet Labs DNS tooling.

Timeline

  • May 2005: First usable ldns 0.50 release with basic DNS and DNSSEC validation.
  • 13 Jun 2005: 0.65 records the repository as online and adds documentation.
  • 18 Oct 2005: 1.0.0 adds drill to ldns, zonefile parsing, an experimental signer, and BSD licensing.
  • 7 Jul 2006: 1.1.0 adds tutorials, documentation, examples, and drill improvements.
  • 28 Nov 2007: 1.2.2 adds ldns-compare-zones and DNSSEC utility fixes.
  • 23 Oct 2012: 1.6.14 adds DANE support, including the ldns-dane example tool.
  • 2020: NLnet Labs places ldns in maintenance mode.
  • 26 Nov 2021: 1.8.0 adds ZONEMD support and SVCB/HTTPS draft support.
  • 4 Dec 2025: 1.9.0 records compact denial of existence support and additional resource-record updates.

Related projects

  • Related NLnet Labs projects include Unbound, NSD, the Rust domain library, dnst, and dnsi. Related DNS standards areas include DNSSEC, TSIG, DANE, NSEC3, ZONEMD, and SVCB/HTTPS.

security posture

Risk level: green

library-like package without higher-risk signals.

Risk classifier

green risk · low confidence · appliance

Why

  • library-like package without higher-risk signals

Signals

  • metadata:library-like

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
drillexecutableindexed executableDiscovered from the local executable index.
ldns-chaosexecutableindexed executableDiscovered from the local executable index.
ldns-compare-zonesexecutableindexed executableDiscovered from the local executable index.
ldns-configexecutableindexed executableDiscovered from the local executable index.
ldns-daneexecutableindexed executableDiscovered from the local executable index.
ldns-dpaexecutableindexed executableDiscovered from the local executable index.
ldns-gen-zoneexecutableindexed executableDiscovered from the local executable index.
ldns-key2dsexecutableindexed executableDiscovered from the local executable index.
ldns-keyfetcherexecutableindexed executableDiscovered from the local executable index.
ldns-keygenexecutableindexed executableDiscovered from the local executable index.
ldns-mxexecutableindexed executableDiscovered from the local executable index.
ldns-notifyexecutableindexed executableDiscovered from the local executable index.
ldns-nsec3-hashexecutableindexed executableDiscovered from the local executable index.
ldns-read-zoneexecutableindexed executableDiscovered from the local executable index.
ldns-resolverexecutableindexed executableDiscovered from the local executable index.
ldns-revokeexecutableindexed executableDiscovered from the local executable index.
ldns-rrsigexecutableindexed executableDiscovered from the local executable index.
ldns-signzoneexecutableindexed executableDiscovered from the local executable index.
ldns-test-ednsexecutableindexed executableDiscovered from the local executable index.
ldns-testnsexecutableindexed executableDiscovered from the local executable index.
ldns-updateexecutableindexed executableDiscovered from the local executable index.
ldns-verify-zoneexecutableindexed executableDiscovered from the local executable index.
ldns-versionexecutableindexed executableDiscovered from the local executable index.
ldns-walkexecutableindexed executableDiscovered from the local executable index.
ldns-zcatexecutableindexed executableDiscovered from the local executable index.
ldns-zsplitexecutableindexed executableDiscovered from the local executable index.
ldnsdexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version1.9.2
manager updated2026-06-22
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:ldns
Version1.9.2
Package managerHomebrew
Homepagehttps://nlnetlabs.nl/projects/ldns/
Last updated2026-06-22T14:05:09-07:00
Pulseupdated
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • Nucleus package database
  • curated package history
  • pkgdb category and tag curation