GOpenCDR / Gelhaus Open Community Domain Registry
Community top-level domains alongside the normal internet, signed from the root down.
An alternative namespace run to infrastructure grade: community TLDs that add names only where the IANA root has none, signed with DNSSEC from a root of their own, served by mirrors anyone can run, with every root change in a public transparency log.
What it is
GOpenCDR, the Gelhaus Open Community Domain Registry, is a namespace of its own that works alongside the normal internet. Its top-level domains live in a root that Gelhaus Solutions operates, and they resolve for anyone whose resolver follows GOpenCDR. Nothing about the IANA namespace changes for anyone else.
IANA always wins
GOpenCDR adds names only where the IANA namespace has none, and three independent layers enforce it: the root's verification gate refuses any string that exists in the IANA root or is on its way there, a blocklist tracks ICANN's pipeline and the special-use registries, and every mirror verifies the IANA root itself and withdraws any overlay that appears in it. A string ICANN delegates is withdrawn everywhere within an hour and blocked for good.
Signed from the root down
Every zone is signed with DNSSEC, algorithm 13, with keys that never leave Vault. Two independent validators check every zone before it is published, every zone carries a ZONEMD digest, and mirrors refuse any copy that fails either check. A resolver that trusts the GOpenCDR anchor can verify every answer back to the root.
Three tiers
Tier 0 is the root registry. Tier 1 is the TLD registries, hosted on the platform by default or run by their operators after technical checks. Tier 2 is the mirrors: public and private resolvers, authoritative secondaries and full zone mirrors, which anyone can run with the GOpenCDR agent as long as they pass conformance.
Everything on the record
Every root change, key event, policy change and abuse action goes into an append-only Merkle log with signed checkpoints, so anyone can check that the root never showed different histories to different people. Every root change needs a second person to approve it, and councils elected by operators and the community decide policy and new TLDs.
Privacy by default
A registration needs an account and a verified email address, and nothing else unless a TLD's own policy asks. RDAP redacts the registrant, the public resolver keeps no query log, and no GOpenCDR site or client carries a tracker.
Legal
Documents that govern GOpenCDR
Terms and privacy
What applies to everyone who uses it.
Security and trust
How to report a vulnerability, and how keys, signatures and certificates are handled.
Registry policies
Who may see registration data, how disputes over names are decided, and who decides.
Agreements
What operators, partners and customers agree to.