# Install ldns with Homebrew

DNS library written in C. Version 1.9.2 via Homebrew; verified 2026-06-22.

## Install

```sh
sudo av install brew:ldns
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install ldns
```

  Evidence: provider-native install command

## Package facts

- **Package key:** brew:ldns
- **Package manager:** Homebrew
- **Version:** 1.9.2
- **Source summary:** DNS library written in C
- **Homepage:** <https://nlnetlabs.nl/projects/ldns/>
- **Last updated:** 2026-06-22T14:05:09-07:00
- **Generated:** 2026-08-03T00:40:33+00:00

## Executables

- drill (alias)
- ldns-chaos (alias)
- ldns-compare-zones (alias)
- ldns-config (alias)
- ldns-dane (alias)
- ldns-dpa (alias)
- ldns-gen-zone (alias)
- ldns-key2ds (alias)
- ldns-keyfetcher (alias)
- ldns-keygen (alias)
- ldns-mx (alias)
- ldns-notify (alias)
- ldns-nsec3-hash (alias)
- ldns-read-zone (alias)
- ldns-resolver (alias)
- ldns-revoke (alias)
- ldns-rrsig (alias)
- ldns-signzone (alias)
- ldns-test-edns (alias)
- ldns-testns (alias)
- ldns-update (alias)
- ldns-verify-zone (alias)
- ldns-version (alias)
- ldns-walk (alias)
- ldns-zcat (alias)
- ldns-zsplit (alias)
- ldnsd (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 1.9.2
## Project history and usage

ldns is NLnet Labs' C library for DNS and DNSSEC programming, accompanied by command-line tools such as drill and many DNSSEC utilities. NLnet Labs describes its goal as simplifying DNS programming in C while supporting low-level DNS and DNSSEC operations.

### Project history

The project appeared in 2005 during the period when DNSSEC tooling was maturing. Its changelog records a first usable 0.50 release in May 2005, an online repository in June 2005, and a 1.0.0 release in October 2005 that added drill to ldns, zonefile parsing, an experimental signer, and a BSD license.

ldns evolved into both a library and a toolbox. Drill, originally important enough that documentation says part of ldns was derived from it, became included in ldns releases from version 1.0.0 onward. The examples directory grew into a collection of practical DNSSEC and zone tools, including signers, validators, key helpers, and packet utilities.

Later releases tracked DNS standards work. The changelog records additions such as NSEC3-related utilities, DANE support in 2012, SVCB/HTTPS support in the 1.8 series, and newer resource-record handling in the 1.9 series. NLnet Labs stated that ldns entered maintenance mode in 2020, with ongoing fixes and occasional experimental use rather than broad feature expansion.

### Adoption history

ldns gained adoption among DNS implementers, operators, and package maintainers because it offered a C API plus ready-to-run diagnostic tools. Distribution packaging reflects that split: some systems package the tools as ldnsutils or drill while others package the library and tools together.

The project also became a bridge between DNS research and production packaging. NLnet Labs explicitly notes use for proof-of-concept work around Internet Drafts, while the maintained command-line tools made it useful for operators who needed DNSSEC-aware zone inspection, signing, verification, and query tracing.

### How it is used

Developers use the library through ldns structures such as resource records, packets, zones, and resolvers. Command-line users most often encounter drill as a dig-like DNS inspection tool and the ldns-* utilities for DNSSEC key, zone, signing, walking, comparison, and verification workflows.

The documentation stresses OpenSSL-backed cryptographic features, optional builds without OpenSSL, IPv4/IPv6 support, TSIG, DNSSEC signing and verification, manual pages, and API documentation.

### Why package nerds care

ldns matters to package nerds because it is a compact DNSSEC lab in package form: a C library, a resolver/query tool, many small executables, optional crypto features, Python bindings, and a long changelog tied to RFC and draft support. It is also a good example of an upstream declaring a maintenance-mode successor path while keeping old Unix packages useful.

NLnet Labs names the Rust domain library as the natural successor to the ldns library, dnst as drop-in replacements for common example utilities, and dnsi as a reimagined DNS inspection tool. That makes ldns a legacy-but-alive package with clear lineage into newer NLnet Labs DNS tooling.

### Timeline

- May 2005: First usable ldns 0.50 release with basic DNS and DNSSEC validation.
- 13 Jun 2005: 0.65 records the repository as online and adds documentation.
- 18 Oct 2005: 1.0.0 adds drill to ldns, zonefile parsing, an experimental signer, and BSD licensing.
- 7 Jul 2006: 1.1.0 adds tutorials, documentation, examples, and drill improvements.
- 28 Nov 2007: 1.2.2 adds ldns-compare-zones and DNSSEC utility fixes.
- 23 Oct 2012: 1.6.14 adds DANE support, including the ldns-dane example tool.
- 2020: NLnet Labs places ldns in maintenance mode.
- 26 Nov 2021: 1.8.0 adds ZONEMD support and SVCB/HTTPS draft support.
- 4 Dec 2025: 1.9.0 records compact denial of existence support and additional resource-record updates.

### Related projects

- Related NLnet Labs projects include Unbound, NSD, the Rust domain library, dnst, and dnsi. Related DNS standards areas include DNSSEC, TSIG, DANE, NSEC3, ZONEMD, and SVCB/HTTPS.

### Sources

- <https://nlnetlabs.nl/documentation/ldns/>
- <https://nlnetlabs.nl/projects/ldns/about/>
- <https://raw.githubusercontent.com/NLnetLabs/ldns/master/Changelog>
- <https://raw.githubusercontent.com/NLnetLabs/ldns/master/README>


## Security Notes

library-like package without higher-risk signals.

- **Geiger risk:** green / low
- library-like package without higher-risk signals


## Combined YAML source

View the package source record on GitHub. [combined/ldns.yml](https://github.com/automic-vault/db/blob/main/combined/ldns.yml)


## Sources

- Nucleus package database
- Geiger risk classifier
- curated package history
- pkgdb category and tag curation
