Back to blog
dns Published: AEU DNS Newsroom

Is DNS Resolution Becoming Too Centralized? New Measurements Paint a Mixed Picture

A new APNIC analysis examines concentration in DNS name registration and resolution markets, revealing a fragmented registrar landscape but a potential concentration of recursive resolver usage.

The Domain Name System (DNS) is often called the internet's phonebook, translating human-friendly domain names into the numerical IP addresses computers use. But beyond this simple role, DNS names have become the stable identifiers for online services, making the system a critical piece of internet infrastructure. If the DNS were to become overly centralized, controlled by just a handful of providers, it could pose risks to competition, resilience, and user privacy. A recent study by Geoff Huston at APNIC re-examines this question, using 2025, 2026 data to measure market concentration in both DNS name registration and DNS resolution.

To measure market dominance, the analysis applies three standard economic metrics. First, the Australian Consumer and Competition Commission threshold of a single entity holding more than 70% of a market signals potential abuse. Second, the four-firm concentration ratio sums the market shares of the top four players; a value above 50% raises concerns. Third, the Herfindahl, Hirschman index (HHI), calculated by squaring each firm's market share and summing the results, indicates moderate concentration above 10% and high concentration above 25%.

Looking first at the DNS name registration market, the data from Domain Name Stat shows a highly fragmented landscape. GoDaddy, the largest registrar, holds only 10.87% of registered domains, followed by NameCheap at 3.67%. The top four registrars together command just 18% of the market, and the HHI is a mere 1.5%. By any metric, the domain name registrar space shows no signs of harmful concentration.

The picture becomes more complex when examining DNS resolution, the actual process of looking up a domain name. When your device needs to resolve a domain, it sends a query to a recursive resolver, which then performs a series of queries to authoritative nameservers to find the answer. APNIC Labs uses a clever measurement technique to estimate how many users rely on each recursive resolver. Online ads deliver a script that generates a unique domain name for each viewer, and the logs from the authoritative server reveal which recursive resolver was used. By mapping the resolver’s IP address to a known open resolver service or an ISP’s infrastructure, researchers can estimate the user population served by each resolver.

The results from 2025, 2026 show that about two-thirds of users direct their DNS queries to the recursive resolver operated by their Internet Service Provider (ISP). Another 15% use a resolver located in the same country but in a different network, which is likely still their ISP using an external resolver. The remainder use well-known open DNS services such as Google Public DNS or Cloudflare’s 1.1.1.1, or cross-border resolvers. While the full distribution of resolver market shares was not disclosed, the heavy reliance on ISP resolvers hints at a potential concentration risk if a few large ISPs dominate a region.

This centralization of recursive resolution matters for several reasons. From a competition standpoint, if most users simply accept their ISP’s default DNS, there is little incentive for ISPs to improve performance, security, or privacy features. From a privacy angle, ISP-operated resolvers can see every domain their customers visit, creating a detailed profile of online activity. Even if the ISP promises not to sell or misuse this data, the sheer volume of information collected can become a target for breaches or government surveillance. Using an encrypted DNS service such as AEU DNS, which supports DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), and DNS-over-QUIC (DoQ) and enforces a strict no-logs policy, can help you retain control over your own browsing history while still enjoying fast and reliable name resolution.

The study also underscores the importance of the recursive resolver market structure for overall internet resilience. If a few large resolver providers were to fail or be attacked, millions of users could lose access to the internet. The current landscape, with a mix of ISP resolvers and open alternatives, provides some diversity, but the real question is whether the open resolver market itself is becoming concentrated. Public data suggests that a small number of public DNS providers serve a significant portion of non-ISP queries, which might warrant closer scrutiny in future measurements.

For everyday internet users, the key takeaway is that while domain name registration is highly competitive, the resolution path your queries take can have profound privacy and reliability implications. Checking your DNS settings and considering a privacy-first resolver are simple steps that can make a difference.

Terms explained

DNS (Domain Name System)
The system that translates human-friendly website names (like www.example.com) into numerical IP addresses that computers use to communicate.
Recursive resolver
A server that receives DNS queries from your device and tracks down the answer by contacting other DNS servers, step by step.
Top-Level Domain (TLD)
The last part of a domain name after the dot, such as .com, .org, or .uk; it is the highest level in the DNS hierarchy.
Herfindahl, Hirschman Index (HHI)
A number used to measure market concentration; a higher index means fewer companies dominate the market.
DNS-over-HTTPS (DoH)
A method that encrypts your DNS queries inside secure web traffic, hiding your browsing activity from your internet provider.
DNS-over-TLS (DoT)
A protocol that wraps your DNS queries in a layer of encryption, preventing anyone on your network from spying on the websites you look up.

How to protect yourself

  1. Check which DNS resolver your device or router uses by looking in your network settings; you can compare it against known privacy-respecting alternatives.
  2. Switch to a DNS service that offers encrypted DNS protocols (DoH, DoT, or DoQ) to prevent your ISP from reading or logging your browsing history.
  3. Choose a DNS resolver that has a published no-logs policy and has been independently audited to verify their privacy claims.
  4. Enable DNSSEC validation on your router or device to protect against DNS spoofing and hijacking attacks.
  5. Regularly review your router’s DNS configuration to ensure no unauthorized changes have been made that could redirect you to malicious sites.

Source: blog.apnic.net

Get private, encrypted DNS