Back to blog
dns Published: AEU DNS Newsroom

Internet Pioneer Behind DNSSEC and Global Domain Standards Receives Dutch Knighthood

Internet Pioneer Behind DNSSEC and Global Domain Standards Receives Dutch Knighthood

Jaap Akkerhuis, a key figure in Europe's first open internet link, DNSSEC signing at scale, and the EPP domain standard, was knighted on April 24, 2026 for exceptional service to society.

Dutch internet pioneer Jaap Akkerhuis was awarded Knight of the Order of the Dutch Lion on April 24, 2026, in Diemen by mayor Erik Boog. This is the highest civilian order of chivalry in the Netherlands, given only to people who have rendered outstanding service to society. Akkerhuis has spent decades working on the Domain Name System (DNS), the internet's phone book that translates human-friendly website names into the numerical addresses computers use to find each other. He is a senior research engineer at NLnet Labs, a protocol designer, and vice-chair of the ISO 3166 Maintenance Agency, the group that maintains official two-letter country codes such as NL for the Netherlands and UK for the United Kingdom.

Since the 1980s, Akkerhuis has worked mostly behind the scenes. He was part of the team at CWI, the Dutch national research institute for mathematics and computer science, that established and operated the first open internet connection between Europe and the United States. That link helped lay the foundation for Amsterdam to become a global internet hub. His early work contributed directly to the spread of the internet in the Netherlands and around the world.

While employed at SIDN, the foundation that runs the .nl country-code domain, Akkerhuis carried out applied research that made it possible to cryptographically sign internet names at scale. This was a milestone in the security of the global DNS because it enabled DNSSEC, a security extension that adds digital signatures to DNS records. DNSSEC lets users and applications verify that a DNS answer really comes from the legitimate owner of a domain and has not been tampered with on the way. In the Internet Engineering Task Force (IETF), the international body where engineers agree on internet standards, Akkerhuis co-chaired the standardisation of automation technology for registering domain names. The resulting standard, known as EPP (Extensible Provisioning Protocol), is still used by domain registrars worldwide to register, transfer, and update domain names reliably.

Akkerhuis also spent 23 years as a member of ICANN's Security and Stability Advisory Committee, where he advised on threats to the stability and security of the internet. ICANN is the organisation that coordinates global domain names and IP addresses. He co-founded and chaired the DNS working group at RIPE, the regional internet registry for Europe, the Middle East, and parts of Central Asia. That group helped operators of critical internet infrastructure, such as large DNS servers and internet service providers, coordinate operationally so that the global DNS remains stable. In 2017, Akkerhuis was recognised as a 'global innovator' and inducted into the Internet Hall of Fame. At NLnet Labs, colleagues value his no-nonsense approach to internet governance and engineering and congratulate him on his well-deserved knighthood. They note that he would probably want the spotlight shared with the many people who worked alongside him.

The recognition of Akkerhuis matters for everyday internet users, website owners, and businesses because the technologies he helped build are woven into almost every online action. When you type a web address, your device performs a DNS lookup. If that lookup is not secure, an attacker could redirect you to a fake website or intercept your traffic. DNSSEC helps prevent certain kinds of spoofing and tampering. EPP allows domain registrars to manage millions of domain names securely and automatically, reducing human errors and downtime. The stability work at ICANN and RIPE helps keep the global DNS from breaking under load or attack. For a modern layer of protection, using a private, encrypted DNS resolver such as AEU DNS adds encryption to your device's name lookups so that outsiders cannot see or alter them, complementing the DNSSEC foundations that pioneers like Akkerhuis helped establish.

Terms explained

Domain Name System (DNS)
The internet's phone book that translates website names like example.com into the numerical IP addresses computers use to find each other.
DNSSEC
A security add-on for DNS that digitally signs DNS records so visitors can be sure the answer has not been tampered with.
EPP
A standard protocol that lets domain registrars automate the registration and management of domain names.
IETF
The international body where engineers agree on the technical standards that make the internet work.
ICANN
The organisation that coordinates global domain names and IP addresses and advises on internet stability and security.
RIPE
One of the regional internet registries that manages IP addresses and provides a forum for European network operators.
ISO 3166 Maintenance Agency
The group that maintains the official two-letter country codes such as NL for the Netherlands and UK for the United Kingdom.

How to protect yourself

  1. Open your router's settings page and find the place where you can change internet or DNS server addresses; replace the automatic addresses with a privacy-focused encrypted DNS provider's addresses, then save and restart the router.
  2. On your phone and computer, turn on encrypted DNS by enabling the 'Private DNS' setting on Android or the 'Secure DNS' option in your web browser, so your website lookups stay private and cannot be easily changed.
  3. If you own a website domain, log in to your domain registrar and look for a DNSSEC option; turn it on and follow the instructions to add the security keys to your domain settings.
  4. Keep your web browser and operating system updated so you get the latest security warnings when a website's address or certificate looks suspicious.
  5. Use two-factor authentication (a second code from an app or text message) on your domain registrar account to stop someone from hijacking your domain and pointing it to a fake site.
  6. For business websites, choose a hosting provider and domain registrar that clearly support DNSSEC and always use HTTPS on your site.

Source: blog.nlnetlabs.nl

Get private, encrypted DNS