Skip to content
Gelhaus Solutions
Apps Services Security Contact
EN DE
Apps / GOpenCDR / GOpenCDR mirror operator terms

GOpenCDR mirror operator terms

What you agree to when you enrol a mirror: enforce the IANA rule, never alter a zone, pass conformance, accept suspension, and use zone files only for serving.

Last updated 27 September 2026 Auf Deutsch lesen →

On this page

  1. What these terms cover
  2. The five rules
  3. The agent
  4. The people who use your mirror
  5. Names and badges
  6. Ending an enrolment
  7. Everything else

What these terms cover

These terms apply when you enrol a mirror with GOpenCDR: a public or private resolver, an authoritative secondary or a full zone mirror that you run with the GOpenCDR mirror agent. You accept them when you enrol, in addition to the GOpenCDR terms and the acceptable use policy.

They cover the open community tier, which any mirror that passes conformance can join. The certified tier, which puts a mirror in GOpenCDR's default pool, needs a separate signed operator agreement and a data processing agreement, with yearly audits and unannounced spot checks.

The five rules

1. IANA always wins

Never answer for a name that exists in the IANA root with anything but the IANA answer. The mirror agent enforces this: it verifies the IANA root itself, refuses to overlay any name in it whatever a bundle says, and withdraws an overlay TLD the moment it appears there. Do not disable, patch around or override that behaviour, and do not serve GOpenCDR zones from a resolver the agent does not manage.

2. Never alter a zone

Serve only zone versions the agent has verified, with their ZONEMD and their DNSSEC chain intact, exactly as published. Do not add, remove or change records, do not rewrite NXDOMAIN, do not inject answers, do not strip DNSSEC, and do not send EDNS Client Subnet upstream. A validating resolver must validate GOpenCDR names against the anchors the agent installs.

3. Pass conformance

A mirror is admitted to a tier, and stays there, only while it passes the automated conformance suite: it validates DNSSEC, serves only verified zone versions, enforces the IANA rule, applies a withdrawal within one hour and serves the current serial within 15 minutes. GOpenCDR probes it continuously. A mirror that fails leaves its tier automatically and returns once it passes again.

A public resolver must also run behind response rate limiting, with minimal ANY answers (RFC 8482), DNS cookies and caps on amplification, and apply source address validation where the network allows it. An open resolver without these is an amplifier aimed at somebody else.

4. Accept suspension

We may suspend your enrolment at once and without prior notice where your mirror fails conformance, breaks these terms, serves wrong data, is compromised or is used for abuse, or where a court, an authority or a collision with the IANA namespace requires it. Suspension revokes the agent's credentials and its access to zone files. We tell you why, and you may ask for a review as the GOpenCDR terms describe. Suspension is not a penalty. It protects everyone who depends on the namespace.

5. Zone files only for serving

TLD zone files are served to enrolled mirrors so that they can answer queries. Use them for that and for verifying them, and for nothing else. Do not publish them, pass them on, sell them, mine them, market to the registrants in them or build lists of registrations from them. When your enrolment ends, delete every copy.

The root zone is public, and this rule does not cover it. A TLD may make its own zone public, or restrict it to certified mirrors.

The agent

We grant you a free, non-exclusive, non-transferable licence to install and run the mirror agent, and the configuration it renders, on systems you control, for as long as your mirror is enrolled and only to operate it. The agent is proprietary. Do not modify it, redistribute it or reverse engineer it beyond what Sections 69d and 69e of the German Copyright Act allow. The licence ends with your enrolment.

Enrolment uses a single-use token. After that, the agent signs every request with its own key; each signature covers the request body, expires within a minute and is accepted once. Keep the key and the token secret, run a current signed release of the agent, which checks the signature of every update before installing it, and tell us at once if a key may be exposed.

The agent reports which zone versions and serials it serves, the results of its own checks, its version and its health. It sends nothing about the people who use your mirror.

The people who use your mirror

You operate your mirror, and you are the controller for anything it records about its users. Publish your own privacy information if the mirror is open to the public. To be admitted to the default pool, a mirror keeps no log that links queries to client addresses for longer than 24 hours, and then only for debugging, and reports only aggregate statistics with minimum counts. We recommend the same for every mirror.

What we hold about you as a mirror operator is described in the privacy notice.

Names and badges

While your mirror is enrolled and passes conformance, you may say that it serves GOpenCDR and show the badge of its tier. Do not suggest that you are GOpenCDR or Gelhaus Solutions, or that a mirror outside the default pool is part of it.

Ending an enrolment

You may retire your mirror at any time from the portal. We may end an enrolment on any ground for suspension, or where GOpenCDR changes or ends the programme. When an enrolment ends, the agent's credentials are revoked, the licence ends and every copy of a TLD zone must be deleted.

Everything else

Enrolment is free. No warranty and no service level apply, in either direction, and liability is as the general terms of service set it out: for what is given away, it is limited to intent and gross negligence (Section 521 BGB). These terms may change through the process in the general terms; an enrolled operator is told of a material change at least six weeks before it takes effect.

Gelhaus Solutions

Self-hosted applications, and the platform that hosts them for the people who would rather not.

Site

  • Apps
  • Security
  • Writing
  • Contact
  • Sitemap

GHub

  • GAdvisory
  • GControl
  • GPlatform Control
  • GPlatform Billing
  • GOpenCDR

Legal

  • Impressum
  • Privacy
  • Terms
  • Data processing
  • Withdrawal
  • Report content

Elsewhere

  • egelhaus@ennogelhaus.de
  • @egelhaus
  • @egelhaus
© 2026 Enno Gelhaus Built and shipped in Germany