Free · No wallet, no coins, no transaction
HNS.ONE runs the services behind a Handshake name: authoritative DNS, hosting, a mailbox, CA-free TLS and a social identity — all on one name. Delegate a name you own, mirror one you already host yourself, or claim a free one. No wallet, no coins, no transaction.
Everything below runs today, on the name you bring or the name you claim.
A real mailbox at you@hns.one backed by a name you control.
JMAP, works in ordinary mail clients.
How it works →
The gateway: your Handshake name mirrored at
yourname.hns.one with an ordinary padlock — send a friend a
link and it works in Chrome, with no software to install.
How it works →
Publish a page to IPFS and point your name at it. Updates are instant and free — no transaction per change.
No Handshake name yet? Claim one under our open registry and everything above works the same.
Enable DANE on your name: the certificate is pinned by the chain, so no certificate authority is trusted at all.
Publish a PGP key for your address and senders find it over Web Key Directory — what GnuPG and Thunderbird look at by default. No keyserver, no trust-on-first-use, and we never see the private half. The DNS record anchored to the Handshake chain is a separate, operator-run step and is not part of publishing a key yet. What that means →
Oblivious DNS (RFC 9230) — the resolver that answers your lookups never learns your address, assuming the relay and the target do not collude. On by default in our browser for Handshake names and ordinary websites. How it works →
Share text the server cannot read — encrypted in your browser, the key never leaves the link. Open it →
Three steps, each of them a button.
app.hns.one — email address and password, nothing else.
Own a TLD from an auction, or a second-level name from Namebase? Publish one TXT record to prove it. Otherwise claim a free name in a click.
Claim your mailbox, publish a page, enable DANE. Each is a button.
That is the quickest path — you publish a single _hnsone
TXT record where you already manage the name, and nothing goes on-chain.
Second-level names work too.
Verify a name you own →
Handshake names resolve natively in Wildroot — verified against the chain, with DANE instead of certificate authorities, and IPFS and Arweave built in. You do not need it to use anything above; it is for browsing the namespace directly, and for getting set up without touching this site at all.
Wildroot has its own home now. Downloads for Windows,
Linux and Android, checksums, release notes and install help all live
at wildroot.io. Older download links
under hns.one/downloads/ keep working.
The browser is software you download and run — no account, no relationship with us. HNS.ONE is the service side: DNS we answer for, mail we hold, certificates we issue. Those are different promises, so they get different sites.
Handshake names do not resolve in Chrome, Safari or Firefox. That is the single biggest thing standing between a name you own and anyone actually visiting it — and it is why we run a gateway.
Every name we serve is also reachable at <name>.hns.one,
over normal DNS with a normal publicly-trusted certificate. Nothing to
install, nothing to configure, and the link works in whatever the person you
sent it to already has open. These are live right now:
hns://14898The content itself is addressed by its IPFS CID, so the gateway can only
point at content — it cannot alter what a CID names. What the gateway does
ask you to trust is that we serve the right records and the right certificate
for your name. That is a real trust, and the honest answer to it is the
browser: Wildroot resolves hns://
straight from the chain with a proof, and checks the certificate against a
DANE pin instead of a certificate authority. The gateway is the on-ramp for
everyone who has not installed it.
yourname.hns.one is an ICANN domain we control, resolved by
ordinary DNS and vouched for by a certificate authority. If we vanished, it
would stop working — your Handshake name would not. Use the gateway link
to reach people, and the native hns:// name as the thing you
actually own.
Things worth knowing before you rely on any of this:
yourname.hns.one terminates TLS on our servers, so we can see
that traffic. The native address is the trustworthy one.