In progress GHub Creator and maintainer Open core 2026 - present

GOpenCDR / Gelhaus Open Community Domain Registry

Community top-level domains alongside the normal internet, signed from the root down.

An alternative namespace run to infrastructure grade: community TLDs that add names only where the IANA root has none, signed with DNSSEC from a root of their own, served by mirrors anyone can run, with every root change in a public transparency log.

What it is

GOpenCDR, the Gelhaus Open Community Domain Registry, is a namespace of its own that works alongside the normal internet. Its top-level domains live in a root that Gelhaus Solutions operates, and they resolve for anyone whose resolver follows GOpenCDR. Nothing about the IANA namespace changes for anyone else.

IANA always wins

GOpenCDR adds names only where the IANA namespace has none, and three independent layers enforce it: the root's verification gate refuses any string that exists in the IANA root or is on its way there, a blocklist tracks ICANN's pipeline and the special-use registries, and every mirror verifies the IANA root itself and withdraws any overlay that appears in it. A string ICANN delegates is withdrawn everywhere within an hour and blocked for good.

Signed from the root down

Every zone is signed with DNSSEC, algorithm 13, with keys that never leave Vault. Two independent validators check every zone before it is published, every zone carries a ZONEMD digest, and mirrors refuse any copy that fails either check. A resolver that trusts the GOpenCDR anchor can verify every answer back to the root.

Three tiers

Tier 0 is the root registry. Tier 1 is the TLD registries, hosted on the platform by default or run by their operators after technical checks. Tier 2 is the mirrors: public and private resolvers, authoritative secondaries and full zone mirrors, which anyone can run with the GOpenCDR agent as long as they pass conformance.

Everything on the record

Every root change, key event, policy change and abuse action goes into an append-only Merkle log with signed checkpoints, so anyone can check that the root never showed different histories to different people. Every root change needs a second person to approve it, and councils elected by operators and the community decide policy and new TLDs.

Privacy by default

A registration needs an account and a verified email address, and nothing else unless a TLD's own policy asks. RDAP redacts the registrant, the public resolver keeps no query log, and no GOpenCDR site or client carries a tracker.