PowerDNS Blog

First alpha release of PowerDNS Recursor 5.5.0

Written by Otto Moerbeek | Aug 13, 2026, 9:01:24 AM

We are proud to announce the first alpha release of PowerDNS Recursor 5.5.0!

Compared to the latest 5.4 release, this pre-release includes the following changes:

  • A feature was added to keep a list of names in the record cache up-to-date, independent of use.
  • Named interfaces can be used to specify source addresses.
  • RPZ updates now wipe relevant entries from the packet cache by default.
  • Protobuf logging can now use a 4 byte framing format and a strategy when sending to multiple remote logging targets.
  • The embedded web server can now read its TLS key and certificate information from an encrypted PKCS12 (pfx) file.
  • Outgoing DOT connections can optionally use a client certificate to provide authentication to an authoritative server or forward target.
  • Optionally an EDE can be emitted if a name is covered by an NTA.

As always, there are also many smaller bug fixes and improvements, please refer to the changelog for additional details. When upgrading do not forget to check the upgrade guide.

Please send us all feedback and issues you might have via the mailing list, or in case of a bug, via GitHub. In particular we would like to see feedback regarding the new DNS cookie support feature.

The tarball (signature) is available from our download server and packages for several distributions are available from our repository.

Older release trains are supported for one year after the following major release. Consult the EOL policy for more details.

We are grateful to the PowerDNS community for the reporting of bugs, issues, feature requests, and especially to the submitters of fixes and implementations of features.