HNS.ONE

Free · No wallet, no coins, no transaction

One identity.
Your site, your mail, your social presence.

HNS.ONE runs the services behind a Handshake name: authoritative DNS, hosting, a mailbox, CA-free TLS and a social identity — all on one name. Delegate a name you own, mirror one you already host yourself, or claim a free one. No wallet, no coins, no transaction.

What you get

Everything below runs today, on the name you bring or the name you claim.

Email at your namelive

A real mailbox at you@hns.one backed by a name you control. JMAP, works in ordinary mail clients. How it works →

An address that just openslive

The gateway: your Handshake name mirrored at yourname.hns.one with an ordinary padlock — send a friend a link and it works in Chrome, with no software to install. How it works →

Hosting on your namelive

Publish a page to IPFS and point your name at it. Updates are instant and free — no transaction per change.

A free namelive

No Handshake name yet? Claim one under our open registry and everything above works the same.

TLS without a CAlive

Enable DANE on your name: the certificate is pinned by the chain, so no certificate authority is trusted at all.

Encryption keys at your namelive

Publish a PGP key for your address and senders find it over Web Key Directory — what GnuPG and Thunderbird look at by default. No keyserver, no trust-on-first-use, and we never see the private half. The DNS record anchored to the Handshake chain is a separate, operator-run step and is not part of publishing a key yet. What that means →

Private DNS lookupsexperimental

Oblivious DNS (RFC 9230) — the resolver that answers your lookups never learns your address, assuming the relay and the target do not collude. On by default in our browser for Handshake names and ordinary websites. How it works →

Encrypted pastebinlive

Share text the server cannot read — encrypted in your browser, the key never leaves the link. Open it →

Getting started

Three steps, each of them a button.

Create an account

app.hns.one — email address and password, nothing else.

Bring a name, or take a free one

Own a TLD from an auction, or a second-level name from Namebase? Publish one TXT record to prove it. Otherwise claim a free name in a click.

Turn things on

Claim your mailbox, publish a page, enable DANE. Each is a button.

Already own a name from Namebase?

That is the quickest path — you publish a single _hnsone TXT record where you already manage the name, and nothing goes on-chain. Second-level names work too. Verify a name you own →

Wildroot, the browser

Handshake names resolve natively in Wildroot — verified against the chain, with DANE instead of certificate authorities, and IPFS and Arweave built in. You do not need it to use anything above; it is for browsing the namespace directly, and for getting set up without touching this site at all.

Wildroot has its own home now. Downloads for Windows, Linux and Android, checksums, release notes and install help all live at wildroot.io. Older download links under hns.one/downloads/ keep working.

Download Wildroot →

Why the split

The browser is software you download and run — no account, no relationship with us. HNS.ONE is the service side: DNS we answer for, mail we hold, certificates we issue. Those are different promises, so they get different sites.

The gateway: Handshake names in an ordinary browser

Handshake names do not resolve in Chrome, Safari or Firefox. That is the single biggest thing standing between a name you own and anyone actually visiting it — and it is why we run a gateway.

Every name we serve is also reachable at <name>.hns.one, over normal DNS with a normal publicly-trusted certificate. Nothing to install, nothing to configure, and the link works in whatever the person you sent it to already has open. These are live right now:

The content itself is addressed by its IPFS CID, so the gateway can only point at content — it cannot alter what a CID names. What the gateway does ask you to trust is that we serve the right records and the right certificate for your name. That is a real trust, and the honest answer to it is the browser: Wildroot resolves hns:// straight from the chain with a proof, and checks the certificate against a DANE pin instead of a certificate authority. The gateway is the on-ramp for everyone who has not installed it.

A gateway address is not a Handshake address.

yourname.hns.one is an ICANN domain we control, resolved by ordinary DNS and vouched for by a certificate authority. If we vanished, it would stop working — your Handshake name would not. Use the gateway link to reach people, and the native hns:// name as the thing you actually own.

Being straight with you

Things worth knowing before you rely on any of this: