LabHub

Blog

Domain & DNS Providers in 2026 — Cloudflare Registrar / Porkbun / Namecheap / Quad9 / NextDNS / dnscontrol Deep Dive

한국어English日本語

Prologue — "Why is buying one domain this complicated?"

Until the mid-2010s, domains were simple. Buy from GoDaddy or Namecheap, use the registrar's default DNS, done. Prices were similar everywhere, and add-on options were minimal.

The 2026 landscape looks completely different. Registration (who records ownership at ICANN/registry) and DNS hosting (who answers your A/AAAA/MX/TXT records) are clearly separated, with two more axes added: public resolvers (what your device queries) and DNS-as-Code (records in git, auto-deployed). Putting each of the four with a different company has become best practice.

Pricing has also changed. The at-cost registration model Cloudflare launched in 2018 (registry wholesale price plus only the ICANN fee) became the comparison benchmark, and legacy registrars who charge margins now have to justify why you should buy the same .com from them. At the same time, new gTLDs like .ai, .dev, .io have crossed $100/year at many registrars due to geopolitical issues and registry price hikes.

And M&A reshaped the landscape. Google Domains was sold to Squarespace in 2023, and Gandi was sold the same year to Total Webhosting Solutions, then nearly doubled prices and lost the trust of long-time users. NS1 was acquired by IBM, becoming part of enterprise DNS hosting, and OpenDNS, absorbed by Cisco long ago, has drifted further from being a free consumer resolver.

This article surveys more than 10 registrars, 7 public resolvers, enterprise DNS like AWS Route 53 and NS1, IaC tools like dnscontrol and Octodns, DNSSEC adoption, and local realities in Korea (Whois, Gabia, KISA) and Japan (Onamae, Muumuu, Value Domain).


1. The 2026 Domain & DNS Map — Four Camps

Running a domain actually splits into four independent decisions.

1. Registrar — Has ICANN accreditation and registers ownership at the registry. For .com it is Verisign, .net also Verisign, .org is PIR. Registrars take domains wholesale from these registries and sell to users. Cloudflare Registrar, Porkbun, Namecheap, Spaceship, NameSilo, Hover, Hostinger, GoDaddy, Squarespace Domains, Gandi, etc.

2. Authoritative DNS hosting — Runs the nameservers that actually hold records for a domain. You can use the registrar's default DNS, but separating is common. Cloudflare DNS, AWS Route 53, NS1 (IBM), DNSimple, deSEC, Bunny DNS, ClouDNS, etc.

3. Public resolver — What your device or network asks "what is example.com?" Explicitly specifying one instead of the ISP default has become the trend. Cloudflare 1.1.1.1, Google 8.8.8.8, Quad9 9.9.9.9, OpenDNS, AdGuard DNS, NextDNS, ControlD.

4. DNS-as-Code (IaC) — Define records in yaml/JS, keep in git, deploy via CI. dnscontrol (Stack Exchange), Octodns (GitHub), Pulumi DNS, Terraform DNS providers.

In the 2010s, putting items 1 through 3 in one place was normal. In 2026, separation is the default. Registration with Cloudflare Registrar at cost, authoritative DNS at the same Cloudflare or Route 53, client resolver at 1.1.1.1 or NextDNS, changes via dnscontrol git workflow. The reason for not trusting all four to one company is simple — even if one breaks, the rest must remain alive so the domain does not die.

Separating registration and DNS is especially safe. If the registrar also holds DNS and your account gets locked, the site disappears entirely in that moment. If DNS is at another company, traffic flows even if the registrar has an incident (as long as expiry is not approaching).


2. Cloudflare Registrar — The At-Cost Standard

Cloudflare Registrar has had one promise since its 2018 launch. Zero margin. They sell at registry wholesale plus only the ICANN fee (18 cents each). If .com wholesale is $9.59, the user pays $9.77. Renewal at the same price. WHOIS privacy free, lock free, DNSSEC free.

Two conditions. (1) You must use Cloudflare DNS. Registering only and putting DNS elsewhere is not allowed. (2) Only some TLDs are supported — about 100 popular TLDs including .com .net .org .io .dev .app. Some like .ai, .me, .co were added late, and ccTLDs like Korea's .kr or Japan's .jp are not yet supported.

Pros.

Cons / constraints.

Practical flow.

1) Add the domain bought elsewhere (e.g., GoDaddy) to Cloudflare and move DNS first
2) Unlock WHOIS and transfer lock, get EPP/Auth code
3) Cloudflare dashboard -> Domain Registration -> Transfer Domains
4) Enter Auth code, one-year renewal auto-added, pay
5) Transfer completes in 5 to 7 days

New registration is also possible in the same dashboard via "Register Domains" for supported TLDs.

The reason Cloudflare Registrar became the de-facto standard in 2026 is clear — price war is meaningless. How do you sell cheaper than zero margin? Other registrars compete on value beyond price (customer support, DNS features, add-on product bundles).


3. Porkbun — Value + Free WHOIS Privacy

Porkbun is a US registrar launched in 2014 that earned the reputation in the 2020s of being "the next cheapest after Cloudflare Registrar, with broad ccTLD support."

Approximate prices in 2026.

Features.

Pros.

Cons.

The reason Porkbun is attractive to indie developers boils down to one thing. "You can buy almost all TLDs from one registrar at similar prices, with free WHOIS, DNSSEC, and email forwarding bundled." Cloudflare Registrar locks DNS, but Porkbun does not, so you can move authoritative DNS to Cloudflare or Route 53 separately.


4. Namecheap + Spaceship — Longtime Favorite and New Brand

Namecheap, founded in 2000, was the most recommended GoDaddy alternative in the 2010s. The frequent question "is Namecheap actually cheap?" has the answer first year cheap, renewal average.

Approximate prices.

Pros.

Cons.

Spaceship — Namecheap's New Brand

In 2023, Namecheap launched a new brand called Spaceship. Same company but separate infrastructure / UI / pricing policy, aimed at a younger, more developer-friendly position.

Reviews are mixed. Spaceship looks like "a new start solving Namecheap's old UX issues," but doubts remain about whether it is truly a separate company since the backend is Namecheap. Many people register new at Spaceship while leaving existing domains at Namecheap.


5. Gandi — TWS Acquisition (2023) Price Controversy

Gandi, founded in 1999 in France, was long beloved by European developers. "No Bullshit" slogan, free SSL, two free mailboxes, clean UI, friendly support — not cheap, but trusted.

In August 2023, Gandi was sold to Total Webhosting Solutions (TWS, Netherlands). The sale itself is common, but events in the months that followed sparked fierce backlash.

The result was mass departure. Hundreds of "moving from Gandi" posts appeared on Hacker News, Reddit, and many developers moved to Porkbun, Cloudflare Registrar, or deSEC (German nonprofit). Some commented "suddenly forcing higher prices on long-loyal premium users was the decisive blow to trust."

In 2026, Gandi still operates and partially adjusted prices, but once-broken trust is hard to recover. "The Gandi lesson" — when a registrar changes hands, pricing policy changes. Options like prepaying five years are a shield, but after five years another company may run things.

Alternatives.


6. Hover (Tucows) / NameSilo / Hostinger / GoDaddy

Hover (Tucows)

Tucows' retail brand. Slogan: "Fair pricing, no upsell." Average pricing (.com about $17 renewal) but distinguished by not pushing SSL/backup/privacy at checkout. WHOIS privacy free by default.

Pros: simplicity, stable company (Tucows is one of the larger ICANN-accredited registrars), clean UI.

Cons: more expensive than Cloudflare / Porkbun. Less appealing for new users.

NameSilo

Known for near-wholesale prices. .com stays around $9.x. WHOIS privacy free, but UI feels dated. Preferred by bulk domain holders (investors, SEO operators).

Hostinger

A hosting company doing registration as a side. Hosting bundles are very cheap — buying hosting + domain + SSL in a 1- to 2-year bundle is very affordable in year one. Renewals return to normal price. Appeals to non-developers wanting hosting and domain in one place.

GoDaddy

The largest registrar in the industry. Still holds the most domains in 2026. Mixed reputation — complex UI and strong upsell, but rich stability/support/tooling. Has a large general-public user share in Korea too.

Pros: largest TLD coverage, 24/7 phone support, many add-ons (website builder, etc.).

Cons: expensive renewal, aggressive checkout upsell, separate WHOIS privacy charge, history of political controversy (2012 SOPA support and ensuing boycott).


7. Squarespace Domains (Google Domains Acquisition 2023)

In June 2023, Google announced selling Google Domains to Squarespace. About 10 million domains were automatically transferred to Squarespace. Google Domains, operated since 2015, was loved for clean UI and reasonable pricing (single $12/year for .com).

The reason for the sale was not clearly disclosed, but industry observation was "Google trimming non-core services." Another cleanup following Stadia and Google Play Music.

Changes after the move to Squarespace.

Reviews.

"The end of Google Domains" was a big event. Even trusted companies can shut down services, and the policies of acquired companies become unpredictable. Together with the Gandi case, it became the basis for the maxim "do not put all domains in one place."


8. DNS Resolvers — Cloudflare 1.1.1.1 / Google 8.8.8.8 / Quad9 / OpenDNS

From here on the story is unrelated to registration. Resolvers are what your device or network asks "what is the IP for this domain?" The default is usually the ISP's resolver, but explicitly specifying another has become common.

ResolverAddressNotes
Cloudflare1.1.1.1 / 1.0.0.1Fastest, privacy-focused, DoH/DoT supported
Google8.8.8.8 / 8.8.4.4Very stable, best global coverage, Anycast
Quad99.9.9.9Malware-domain blocking, Swiss nonprofit, no logs
OpenDNS208.67.222.222Cisco-owned, family filter option, separate business version
AdGuard DNS94.140.14.14Ad / tracker blocking
NextDNSper-accountCustom blocklists, logs / dashboard
ControlDper-accountSame category, more powerful policy

Cloudflare 1.1.1.1

Launched 2018. Obtained 1.1.1.1 in partnership with APNIC. Consistently top in performance benchmarks. Supports both DoH (DNS over HTTPS) and DoT (DNS over TLS). Policy of logs kept 24 hours then deleted audited by KPMG. Family-protection variants exist (1.1.1.2 malware block, 1.1.1.3 malware + adult block).

Google 8.8.8.8

Launched 2009. Oldest public resolver. Largest Anycast network. Performance is consistent and stable, but privacy policy is less strict than Cloudflare (no full log-deletion promise). Works as a default anywhere.

Quad9 9.9.9.9

Launched 2017. Malware / phishing domain blocking resolver in partnership with IBM X-Force. Operated by Swiss nonprofit (Quad9 Foundation), keeps no logs. Blocking data based on threat intelligence from 18+ security companies. Slightly slower but suited to security-first environments.

OpenDNS

Originally launched 2005 as an independent company, acquired by Cisco in 2015. A free consumer version and paid Umbrella (enterprise) split. Family filter (FamilyShield: 208.67.222.123) is a strength. Updates for consumer features stagnated after Cisco acquisition.

AdGuard DNS

Specialized in ad / tracker blocking. Two modes — "Default" (ad / tracker block) and "Family Protection" (adding adult content blocking). Free public + paid premium (personal dashboard, stronger blocking).


9. Family DNS — NextDNS / ControlD / AdGuard

Among resolvers, the category that provides family / organizational filtering and dashboards. Adoption in homes / small offices grew rapidly through 2026.

NextDNS

Launched 2019, France. Each user / org creates their own resolver profile. Choose blocklists (EasyList, AdGuard, OISD, dozens more), domain whitelist / blacklist, force safe search, SafeSearch, parental controls (age-based category blocking). Realtime query logs in dashboard. Supports both DoH and DoT.

ControlD

Launched 2020. Similar concept to NextDNS but policy controls are finer. Time-based policies (block social media during work hours), location-based policies (home / office), per-device policies. Their own IPv4 Anycast and BYOIP options.

AdGuard DNS (Pro)

Paid dashboard version offered by AdGuard. Strong in ad-blocking. Integrated with the mobile app (AdGuard for Android/iOS) for system-wide ad blocking.

Family DNS Selection Guide


10. AWS Route 53 / NS1 (IBM) — Enterprise DNS Hosting

Authoritative DNS hosting in enterprise environments is a different market. Core requirements differ — Anycast global coverage, 99.999%+ SLA, traffic routing policies (geo / latency / weight), Health Checks, large zones (tens of thousands of records), API / Terraform integration.

AWS Route 53

AWS DNS service. Global Anycast network, 100% SLA announced (historically near zero downtime). Pricing about $0.50/month per zone, $0.40 per million queries.

Features.

Standard choice for enterprises. The integration with AWS infra is powerful, so nearly every company running on AWS uses Route 53.

NS1 (IBM)

Originally NS1 was a leader in traffic routing. Data-driven DNS — combining RUM, external monitoring, and internal metrics to return the best IP per user. IBM acquired in 2022, then integrated as the IBM NS1 Connect brand.

Pros.

Cons.

As alternatives, DNSimple, Bunny DNS, ClouDNS, Constellix target the mid-market. deSEC is a nonprofit offering free DNS hosting (Germany).


11. DNSSEC Adoption in 2026

DNSSEC (DNS Security Extensions) is a standard for signing DNS responses to prevent tampering. First RFC in 1997, root zone signed in the 2010s, but adoption stayed low for a long time.

In 2026.

Barriers.

  1. Key management is complex — KSK rollover, ZSK rollover, DS record registration.
  2. Misconfiguration takes the whole domain down — signature expiry, algorithm mismatch.
  3. Insufficient CDN / Cloud DNS automation — Cloudflare is one click, others manual.
  4. Low awareness — general developers do not feel the need.

Recommendations.

DNSSEC alone does not block every attack. DoH/DoT (transport encryption), DANE/TLSA (cert pinning), and CAA records (cert-issuance restriction) need to come along for completeness.


12. DNS as Code — dnscontrol / Octodns / Pulumi DNS

The era of touching records by hand in a GUI is over. The flow of keeping DNS records in git, deploying via CI after PR review has been standard since the mid-2020s.

dnscontrol (Stack Exchange)

A tool Stack Exchange built for its own DNS operations. Records expressed in a JavaScript DSL.

var REG_NONE = NewRegistrar('none')
var DNS_CF = NewDnsProvider('cloudflare')

D(
  'example.com',
  REG_NONE,
  DnsProvider(DNS_CF),
  A('@', '192.0.2.1'),
  CNAME('www', '@'),
  MX('@', 10, 'mx1.example.com.'),
  TXT('@', 'v=spf1 include:_spf.google.com ~all')
)
dnscontrol preview   # preview changes
dnscontrol push      # apply

Supported providers: Cloudflare, Route 53, NS1, Google Cloud DNS, Azure, GoDaddy, Namecheap, DigitalOcean, Hetzner, Linode, Vultr, deSEC, Porkbun, and 40+ more.

Pros: multi-provider — deploy the same zone to two places at once (Cloudflare + Route 53). Active-Active DNS operations.

Octodns (GitHub)

A tool GitHub built for its zone management. Records defined in YAML.

# example.com.yaml
'':
  - type: A
    value: 192.0.2.1
www:
  - type: CNAME
    value: example.com.
'@':
  - type: MX
    values:
      - { preference: 10, exchange: mx1.example.com. }
octodns-sync --config-file config.yaml --doit

Supported providers: Cloudflare, Route 53, Azure, NS1, Constellix, DNSimple, DigitalOcean, Google Cloud DNS, OVH, PowerDNS, Hetzner, deSEC, dnsimple, and more.

Difference from dnscontrol: YAML declaration is cleaner for code review, and multi-provider support is strong, but dnscontrol's DSL is more expressive.

Pulumi DNS / Terraform DNS

General-purpose IaC tools' DNS modules. The advantage is managing in the same code as infrastructure. The downside is weaker DNS-specific niceties (multi-provider sync deploy, equivalence comparison).

Who Uses What


13. New gTLD Explosion — .dev / .ai / .io Get Expensive

ICANN's 2012 new gTLD program launched over 1,000 new TLDs including .app, .dev, .blog, .shop. Most started cheap, but several rose sharply after 2024.

.ai — AI Boom Beneficiary

.ai is the ccTLD of Anguilla (British Caribbean island). Demand exploded with the AI boom, prices rose. About $80 in 2024, about $100 to $150 in 2026 (varies by registrar). Reports say the Anguilla government earns one-third of GDP just from .ai license revenue.

.io — British Indian Ocean Territory (similar trajectory to .ai)

Loved by startups / developers. From about $40 in 2024 to about $50 to $70 in 2026. There are political issues too — the UK's decision to cede the Chagos Islands to Mauritius could affect .io's future (possibility of IANA retiring the ccTLD).

.dev — Operated by Google

A gTLD Google operates. All .dev domains are HSTS-preload enforced (HTTPS required). Pricing is stable at about $17/year. Popular for developer projects hosting.

.app — Also Google, HSTS-preload enforced

Popular for mobile app pages. Pricing around $20/year.

.com — Still the Standard

Operated by Verisign. Wholesale pricing rises periodically per the agreement with ICANN (capped at 7% per year). About $10 wholesale in 2026. At this price it is cheaper than many new gTLDs.

Cautions When Using New gTLDs


14. Korea — Whois, Gabia, KISA

Special features of the Korean domain market.

.kr Domain

KISA (Korea Internet & Security Agency) runs the .kr registry. All .kr domains can only be registered through KISA-certified Korean registrars — foreign registrars (Cloudflare, Porkbun, etc.) cannot directly sell .kr (some offer it via reseller).

Major Korean registrars.

.kr Policy

When Buying Domains in Korea

KISA's Role

DNS Hosting

Large sites typically use Cloudflare DNS or Route 53 directly. Korean native DNS hosting services exist, but global services dominate in global Anycast coverage.


15. Japan — Onamae / Muumuu / Value Domain

The landscape of the Japanese domain market.

.jp Domain

JPRS (Japan Registry Services) operates the .jp registry. .co.jp (corporation), .ne.jp (network), .or.jp (nonprofit), .ac.jp (education), .go.jp (government) — segmented second-level domains are a feature.

Major Japanese Registrars

The GMO group effectively oligopolizes the Japanese domain market. Pricing is slightly higher than overseas registrars (Porkbun, Cloudflare), but .jp registration is procedurally easier via a Japanese registrar.

.jp Policy

When Buying Domains in Japan


16. Who Should Choose What — Scenario-Based Recommendations

Let us group the tools by scenario.

Indie Developer, 1 to 3 Domains

Startup, 5 to 20 Domains

Mid-Size Company, Dozens to Hundreds of Domains

Family / Home (Child Protection)

Privacy Obsessed

Politically Risky Content


17. Frequently Asked Operational Questions

Q. Does moving registrars take the site down?

A. No. Registrar transfer only moves the ownership record, traffic flows if authoritative DNS stays. But if you move authoritative DNS together when changing registrars, misconfiguration can cause downtime. The order should be: DNS transfer, stabilize for a few days, then registrar transfer.

Q. Should WHOIS privacy always be on?

A. For general users, yes. You become a target of spam / phishing / social engineering. However, some ccTLDs (like .us) restrict WHOIS privacy.

Q. What is Transfer Lock?

A. An anti-hijacking device. When on, separate unlock is needed for transfer to another registrar. Keep it on normally, turn off only during transfer.

Q. What is the EPP / Auth code?

A. Authentication code needed during domain transfer. Get it from the current registrar, input at the new registrar. Must be used within a few days of issuance.

Q. How long is the recovery window after domain expiry?

A. Per ICANN policy, 30 days grace period (renewal at normal price), then 30 to 80 days redemption period (fee about $100 to $200), then release. Auto-renewal and payment-method backup are safe.

Q. How long does DNS change take to propagate (TTL)?

A. Depends on the TTL value of the record. Default is usually 300 to 3,600 seconds. Lowering TTL to 60 seconds just before change propagates faster.

Q. How do multi-provider DNS (two providers running simultaneously)?

A. Register both companies' nameservers together in the registrar NS settings, then sync-deploy the same zone to both via dnscontrol / Octodns. If one goes down, the other answers.

Q. .ai got suddenly expensive, what to do?

A. Anguilla government's pricing policy change plus rising demand. Lock with multi-year payment just before renewal, or consider alternative TLDs (.dev, .app).


Closing — Separation, Automation, Backup

If we sum up domain and DNS best practice in 2026 in one line — separate, automate, back up.

Gandi raising prices, Google Domains being sold, NS1 being acquired by IBM — all teach the same lesson. Companies change. Policies change. If you put everything in one place, when that company changes your entire infra shakes.

There is no guarantee Cloudflare Registrar's at-cost prices will last forever. Still, if you run a separated structure, even if the registrar changes DNS lives on, even if DNS provider changes the registrar stays, even if a resolver is blocked you can pivot to another resolver. This layered defense is the core of domain operations in 2026.


References

Comments

No comments yet.

Sign in to leave a comment