Definition · DNS & Email Spoofing

What is DNSSEC?

DNS Security Extensions (DNSSEC), specified in RFC 4033, RFC 4034 and RFC 4035, address a structural weakness in DNS: a resolver receiving an answer has no way to tell whether it came from the real authoritative server or from an attacker who got a forged response in first. DNSSEC signs the records in a zone, so a validating resolver can check the signature before trusting the data.

Crucially, DNSSEC does not encrypt anything. Queries and answers remain readable on the wire — that is the problem DNS over HTTPS addresses, and the two are complementary rather than alternatives.

The record types involved

  • RRSIG — the signature over a set of records of the same name and type
  • DNSKEY — the public keys used to verify those signatures
  • DS — a digest of a child zone’s key, published in the parent zone
  • NSEC / NSEC3 — authenticated denial of existence, proving a name really is absent

The DS record is what makes validation transitive: the root zone’s key is configured as a trust anchor, the root signs a DS for .com, .com signs a DS for example.com, and so on down. A resolver that can follow that chain treats the zone as signed and validated; a failed check returns SERVFAIL rather than a wrong answer.

What it enables and what it costs

Validated DNS is a prerequisite for protocols that put trust in DNS data. DANE/TLSA — binding a certificate to a service through DNS — only makes sense over DNSSEC, which is why it appears in mail transport hardening discussions alongside MTA-STS. Authenticated answers also make tampering with SPF, DKIM or CAA records detectable rather than silent.

The operational cost is real. Signatures expire, so a zone whose signing has stalled will fail validation and become unreachable for validating resolvers even though the records are intact. Key rollovers must be coordinated with the parent’s DS record, and a mismatch there breaks the chain. These outages are self-inflicted rather than adversarial, and they are the main reason adoption remains uneven.

See DNS record types, NS records for how delegation and DS records pair up, DNS propagation for the caching behaviour that also applies to signatures, and defence in depth for where DNS integrity sits among other controls.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.