DNSSEC

DNSSEC (DNS Security Extensions): signing, validation, trust anchors, NSEC/NSEC3

DNSSEC RFCs (86)

Display RFCs as
  • RFC 10026: BCP 246: Operational Recommendations for DNSSEC Delegation Signer (DS) Automation

    Best Current Practice
  • RFC 9975: Clarifications on CDS/CDNSKEY and CSYNC Consistency

    Proposed Standard
  • RFC 9904: DNSSEC Cryptographic Algorithm Recommendation Update Process

    Proposed Standard
  • RFC 9905: Deprecating the Use of SHA-1 in DNSSEC Signature Algorithms

    Proposed Standard
  • RFC 9906: Deprecate Usage of ECC-GOST within DNSSEC

    Proposed Standard
  • RFC 9859: Generalized DNS Notifications

    Proposed Standard
  • RFC 9824: Compact Denial of Existence in DNSSEC

    Proposed Standard
  • RFC 9726: BCP 241: Operational Considerations for Use of DNS in Internet of Things (IoT) Devices

    Best Current Practice
  • RFC 9718: DNSSEC Trust Anchor Publication for the Root Zone

    Informational
  • RFC 9563: SM2 Digital Signature Algorithm for DNSSEC

    Informational
  • RFC 9615: Automatic DNSSEC Bootstrapping Using Authenticated Signals from the Zone's Operator

    Proposed Standard
  • RFC 9558: Use of GOST 2012 Signature Algorithms in DNSKEY and RRSIG Resource Records for DNSSEC

    Informational
  • RFC 9364: BCP 237: DNS Security Extensions (DNSSEC)

    Best Current Practice
  • RFC 9276: BCP 236: Guidance for NSEC3 Parameter Settings

    Best Current Practice
  • RFC 9157: Revised IANA Considerations for DNSSEC

    Proposed Standard
  • RFC 9102: TLS DNSSEC Chain Extension

    Experimental
  • RFC 9077: NSEC and NSEC3: TTLs and Aggressive Use

    Proposed Standard
  • RFC 8976: Message Digest for DNS Zones

    Proposed Standard
  • RFC 8901: Multi-Signer DNSSEC Models

    Informational
  • RFC 8749: Moving DNSSEC Lookaside Validation (DLV) to Historic Status

    Proposed Standard
  • RFC 8683: Additional Deployment Guidelines for NAT64/464XLAT in Operator and Enterprise Networks

    Informational
  • RFC 8624: Algorithm Implementation Requirements and Usage Guidance for DNSSEC

    Proposed Standard

    Obsoleted by RFC 9904

  • RFC 8509: A Root Key Trust Anchor Sentinel for DNSSEC

    Proposed Standard
  • RFC 8483: Yeti DNS Testbed

    Informational
  • RFC 8198: Aggressive Use of DNSSEC-Validated Cache

    Proposed Standard
  • RFC 8145: Signaling Trust Anchor Knowledge in DNS Security Extensions (DNSSEC)

    Proposed Standard
  • RFC 8078: Managing DS Records from the Parent via CDS/CDNSKEY

    Proposed Standard
  • RFC 8080: Edwards-Curve Digital Security Algorithm (EdDSA) for DNSSEC

    Proposed Standard
  • RFC 8027: BCP 207: DNSSEC Roadblock Avoidance

    Best Current Practice
  • RFC 7958: DNSSEC Trust Anchor Publication for the Root Zone

    Informational

    Obsoleted by RFC 9718

  • RFC 7901: CHAIN Query Requests in DNS

    Experimental
  • RFC 7828: The edns-tcp-keepalive EDNS0 Option

    Proposed Standard
  • RFC 7583: DNSSEC Key Rollover Timing Considerations

    Informational
  • RFC 7646: Definition and Use of DNSSEC Negative Trust Anchors

    Informational
  • RFC 7344: Automating DNSSEC Delegation Trust Maintenance

    Proposed Standard
  • RFC 7250: Using Raw Public Keys in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)

    Proposed Standard
  • RFC 7218: Adding Acronyms to Simplify Conversations about DNS-Based Authentication of Named Entities (DANE)

    Proposed Standard
  • RFC 7129: Authenticated Denial of Existence in the DNS

    Informational
  • RFC 6975: Signaling Cryptographic Algorithm Understanding in DNS Security Extensions (DNSSEC)

    Proposed Standard
  • RFC 6944: Applicability Statement: DNS Security (DNSSEC) DNSKEY Algorithm Implementation Status

    Proposed Standard

    Obsoleted by RFC 8624

  • RFC 6840: Clarifications and Implementation Notes for DNS Security (DNSSEC)

    Proposed Standard
  • RFC 6844: DNS Certification Authority Authorization (CAA) Resource Record

    Proposed Standard

    Obsoleted by RFC 8659

  • RFC 6841: A Framework for DNSSEC Policies and DNSSEC Practice Statements

    Informational
  • RFC 6781: DNSSEC Operational Practices, Version 2

    Informational
  • RFC 6725: DNS Security (DNSSEC) DNSKEY Algorithm IANA Registry Updates

    Proposed Standard
  • RFC 6698: The DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS) Protocol: TLSA

    Proposed Standard
  • RFC 6604: xNAME RCODE and Status Bits Clarification

    Proposed Standard
  • RFC 6605: Elliptic Curve Digital Signature Algorithm (DSA) for DNSSEC

    Proposed Standard
  • RFC 6014: Cryptographic Algorithm Identifier Allocation for DNSSEC

    Proposed Standard
  • RFC 5933: Use of GOST Signature Algorithms in DNSKEY and RRSIG Resource Records for DNSSEC

    Historic
  • RFC 5910: Domain Name System (DNS) Security Extensions Mapping for the Extensible Provisioning Protocol (EPP)

    Proposed Standard
  • RFC 5702: Use of SHA-2 Algorithms with RSA in DNSKEY and RRSIG Resource Records for DNSSEC

    Proposed Standard
  • RFC 5155: DNS Security (DNSSEC) Hashed Authenticated Denial of Existence

    Proposed Standard
  • RFC 5074: DNSSEC Lookaside Validation (DLV)

    Historic
  • RFC 5011: STD 74: Automated Updates of DNS Security (DNSSEC) Trust Anchors

    Internet Standard
  • Informational
  • RFC 4955: DNS Security (DNSSEC) Experiments

    Proposed Standard
  • RFC 4956: DNS Security (DNSSEC) Opt-In

    Experimental
  • RFC 4471: Derivation of DNS Name Predecessor and Successor

    Experimental
  • RFC 4641: DNSSEC Operational Practices

    Informational

    Obsoleted by RFC 6781

  • RFC 4509: Use of SHA-256 in DNSSEC Delegation Signer (DS) Resource Records (RRs)

    Proposed Standard
  • RFC 4470: Minimally Covering NSEC Records and DNSSEC On-line Signing

    Proposed Standard
  • RFC 4431: The DNSSEC Lookaside Validation (DLV) DNS Resource Record

    Historic
  • RFC 4255: Using DNS to Securely Publish Secure Shell (SSH) Key Fingerprints

    Proposed Standard
  • RFC 4310: Domain Name System (DNS) Security Extensions Mapping for the Extensible Provisioning Protocol (EPP)

    Proposed Standard

    Obsoleted by RFC 5910

  • RFC 4033: DNS Security Introduction and Requirements

    Proposed Standard
  • RFC 4034: Resource Records for the DNS Security Extensions

    Proposed Standard
  • RFC 4035: Protocol Modifications for the DNS Security Extensions

    Proposed Standard
  • RFC 3845: DNS Security (DNSSEC) NextSECure (NSEC) RDATA Format

    Proposed Standard

    Obsoleted by RFC 4033, RFC 4034, RFC 4035

  • RFC 3755: Legacy Resolver Compatibility for Delegation Signer (DS)

    Proposed Standard

    Obsoleted by RFC 4033, RFC 4034, RFC 4035

  • RFC 3757: Domain Name System KEY (DNSKEY) Resource Record (RR) Secure Entry Point (SEP) Flag

    Proposed Standard

    Obsoleted by RFC 4033, RFC 4034, RFC 4035

  • RFC 3225: Indicating Resolver Support of DNSSEC

    Proposed Standard
  • RFC 3226: DNSSEC and IPv6 A6 aware server/resolver message size requirements

    Proposed Standard
  • RFC 3130: Notes from the State-Of-The-Technology: DNSSEC

    Informational
  • RFC 3090: DNS Security Extension Clarification on Zone Status

    Proposed Standard

    Obsoleted by RFC 4033, RFC 4034, RFC 4035

  • RFC 3007: Secure Domain Name System (DNS) Dynamic Update

    Proposed Standard
  • RFC 3008: Domain Name System Security (DNSSEC) Signing Authority

    Proposed Standard

    Obsoleted by RFC 4033, RFC 4034, RFC 4035

  • RFC 2535: Domain Name System Security Extensions

    Proposed Standard

    Obsoleted by RFC 4033, RFC 4034, RFC 4035

  • RFC 2536: DSA KEYs and SIGs in the Domain Name System (DNS)

    Proposed Standard
  • RFC 2537: RSA/MD5 KEYs and SIGs in the Domain Name System (DNS)

    Proposed Standard

    Obsoleted by RFC 3110

  • RFC 2538: Storing Certificates in the Domain Name System (DNS)

    Proposed Standard

    Obsoleted by RFC 4398

  • RFC 2539: Storage of Diffie-Hellman Keys in the Domain Name System (DNS)

    Proposed Standard
  • RFC 2540: Detached Domain Name System (DNS) Information

    Experimental
  • RFC 2541: DNS Security Operational Considerations

    Informational

    Obsoleted by RFC 4641

  • RFC 2137: Secure Domain Name System Dynamic Update

    Proposed Standard

    Obsoleted by RFC 3007

  • RFC 2065: Domain Name System Security Extensions

    Proposed Standard

    Obsoleted by RFC 2535

Subscribe to DNSSEC

Get notified when:

  • RFC changes to status, obsoleted by, updates, updated by, or subseries.
  • New RFC added to this subject or below
  • The subject was merged into another.