The 99.2% Gas Cut Nobody Talked About: How ENS Quietly Fixed DNSSEC for Ordinary Users

A new ENS research report measures the impact of EIP-7951's P-256 precompile on DNSSEC verification costs, revealing a 99.2% gas reduction that makes importing real-world domains into ENS economically viable for ordinary users.

· Updated October 5, 2026 · Zain Tran · 6 min read · 3 total views · 3 today

Categories: technology

Futuristic editorial illustration of Ethereum gas optimization for DNSSEC domain verification

I was watching a friend try to import her .com domain into ENS last year. The transaction failed three times. Each failure cost her about forty dollars in gas. She stared at the screen and asked me the same question I have heard a hundred times: "Why does proving I own my own domain cost more than the domain itself?"

The answer was buried in the Ethereum Virtual Machine, grinding through elliptic-curve arithmetic one opcode at a time. That changed on December 3, 2025, when the Fusaka upgrade shipped EIP-7951 — the P-256 precompile — and ENS Labs flipped the switch. A new research report published September 1, 2026 measures exactly what happened next. The numbers are stark. The implications are bigger than most people realize.

Key Metrics at a Glance

Metric Value
Gas Reduction (Algorithm 13 Verification Step) 99.2%
Precompile Gas Cost (EIP-7951) 6,900 gas
Pre-Fusaka Method EVM opcode-based elliptic-curve arithmetic
Affected DNSSEC Algorithm ECDSAP256SHA256 (Algorithm 13)
Share of Second-Level Domains Impacted Large majority of modern TLDs
Precompile Live Since December 3, 2025 (Fusaka Upgrade)
Report Published September 1, 2026

What Actually Changed

Before Fusaka, ENS verified DNSSEC signatures inside smart contracts using pure EVM bytecode. Algorithm 13 — the ECDSA P-256 standard that powers most modern top-level domains — required the contract to perform elliptic-curve point multiplication, addition, and modular arithmetic step by step. Every opcode cost gas. The verification of a single leaf signature in the DNSSEC chain of trust could burn through hundreds of thousands of gas.

The result was predictable. Importing a DNS name into ENS became a luxury transaction. Users paid not for the value of the name, but for the computational overhead of proving cryptographically that they owned it.

Ethereum Virtual Machine processing elliptic-curve arithmetic for DNSSEC verification

EIP-7951 changed the architecture. It added a native precompile at address 0x0b that performs P-256 signature verification at the protocol level. Instead of emulating the math in bytecode, the EVM hands it to a native routine. The research report from ENS Labs, authored by contributor Marcus, re-executed every DNS import ENS has recorded against both the old and new verifier. The finding: the P-256 verification step dropped by 99.2%.

That is not an optimization. That is a demolition.

The Competitive Landscape: Where Does ENS Stand?

Protocol / Service On-Chain DNSSEC Verification Gas Optimization Precompile Support User Cost Trend
ENS (Post-Fusaka) Full chain-of-trust 99.2% reduction EIP-7951 P-256 Decreasing
ENS (Pre-Fusaka) Full chain-of-trust None None High / Volatile
Handshake (HNS) Native on-chain names N/A (own chain) N/A Low but limited
Unstoppable Domains L2/bridged claims Moderate Limited Moderate
Traditional DNS Off-chain only N/A N/A Flat / Hidden

The table tells a clear story. ENS was the only major naming system attempting full on-chain DNSSEC verification on Ethereum L1. That ambition made it expensive. The precompile does not just lower costs — it makes the original vision economically viable.

The Technical Translation

A precompile is a shortcut. The EVM recognizes a specific contract address and routes the call to native code instead of executing bytecode. Before EIP-7951, Ethereum had precompiles for elliptic curves like secp256k1 and bn256, but not for the NIST P-256 curve that DNSSEC Algorithm 13 requires.

The gap was not trivial. Every time a user tried to import a .com, .org, or .net domain, the ENS contract had to verify a chain of signatures from the IANA root down to the second-level domain. If any step in that chain used Algorithm 13, the contract paid the full EVM price.

Now it pays 6,900 gas. At current prices, that is pennies instead of dollars. The difference between a failed experiment and a usable product.

User successfully importing a DNS domain into ENS with minimal gas fees

Who Benefits, and Who Still Pays

The immediate winners are ordinary users who want to bridge their existing internet identity into Ethereum. A developer running a small business can now import her company domain without burning a day's wages on gas. A journalist can verify his .org without calculating whether the transaction cost exceeds the story budget.

But there is a broader winner: the credibility of on-chain identity itself. ENS has always claimed that it could verify real-world DNS ownership trustlessly. The claim was true in theory and punishing in practice. Now it is true at a price point that does not punish the user for believing in it.

The remaining cost is not gas. It is complexity. DNSSEC itself is still a maze of records, keys, TTLs, and registries. The precompile fixes the Ethereum side of the equation. It does not fix the user experience of configuring DNSSEC at a traditional registrar. That work remains.

The Accountability Layer

Here is what the report does not say loudly enough. The P-256 precompile was proposed, debated, and delayed for years before it reached mainnet. During those years, users absorbed the cost of the delay. Every failed import, every abandoned transaction, every decision to use a centralized alternative instead — that was the price of a protocol that moved slower than the problem it was supposed to solve.

The research is excellent. The data is rigorous. But it arrives ten months after the upgrade, which means the ecosystem spent nearly a year without a public accounting of one of the most significant user-facing improvements in ENS history.

ENS Labs should publish these measurements faster. If a 99.2% cost reduction is not worth a prompt report, what is?

Strategic Implications and Future Outlook

Futuristic visualization of Ethereum P-256 precompile enabling multiple protocol use cases beyond ENS

The P-256 precompile opens doors beyond ENS. Any protocol that needs to verify P-256 signatures on Ethereum L1 can now do so efficiently. That includes:

  • Passkey and WebAuthn authentication flows
  • Government-issued digital identity verification
  • Cross-chain bridges relying on standard cryptographic curves
  • Enterprise compliance tools requiring NIST-approved algorithms

ENS was the proof of concept. The rest of the ecosystem should follow.

One risk remains: reliance on a single precompile address. If a future hard fork modifies or replaces EIP-7951, contracts that depend on it will need upgrades. ENS uses proxies and governance for exactly this reason, but not every protocol plans that carefully.

TL;DR

  • What: ENS's P-256 precompile reduced DNSSEC Algorithm 13 verification gas costs by 99.2%
  • Why: EIP-7951 (Fusaka upgrade, Dec 2025) replaced EVM opcode-based elliptic-curve math with a native precompile at 6,900 gas
  • Impact: Importing .com/.org/.net domains into ENS is now economically viable for ordinary users instead of prohibitively expensive
  • Watch: Whether other protocols adopt P-256 for passkeys, identity, and cross-chain verification; whether ENS publishes impact reports faster after future upgrades

Sources


Zain Tran is TotesTek's Ethereum Ecosystem Columnist & Accountability Reporter. He writes about Ethereum, ETH, smart contracts, DeFi, Layer 2 networks, staking, validators, and the real-world consequences of technical and financial failure.