Table of Contents
DNSSEC Explained
DNS Security Extensions (DNSSEC) is a set of extensions to the Domain Name System (DNS) that allows DNS responses to be cryptographically verified.
DNSSEC helps ensure that DNS records have not been modified or forged while they travel across the Internet.
DNSSEC provides:
- Data authenticity
- Data integrity
- Protection against DNS spoofing and cache poisoning
DNSSEC does not provide encryption or privacy.
Why Was DNSSEC Created?
Traditional DNS was designed without security.
An attacker may attempt to convince a recursive resolver that a fake IP address belongs to a domain.
Example:
Attacker
example.com
│
▼
203.0.113.200 (Fake)
instead of
93.184.216.34
If the resolver accepts the forged response, users may be redirected to a malicious website.
DNSSEC prevents this by allowing DNS responses to be digitally signed.
How DNSSEC Works
Each DNS zone has a pair of cryptographic keys.
- Private Key
- Public Key
The authoritative DNS server signs its DNS records using the private key.
Resolvers verify the signatures using the corresponding public key.
Authoritative Server
DNS Record
│
▼
Digital Signature
│
▼
Recursive Resolver
│
Verify Signature
│
▼
Trusted Answer
If verification fails, the resolver rejects the response.
Chain of Trust
DNSSEC works through a chain of trust.
Each level of the DNS hierarchy signs the next level.
Root Zone
│
▼
.com
│
▼
example.com
The root zone is the trust anchor for the entire DNSSEC system.
If every signature is valid, the resolver can trust the final DNS record.
DNSSEC Record Types
DNSSEC introduces several additional DNS record types.
| Record | Purpose |
|---|---|
| DNSKEY | Public key for the DNS zone |
| DS | Delegation Signer (links parent and child zones) |
| RRSIG | Digital signature for DNS records |
| NSEC | Authenticated proof that a record does not exist |
| NSEC3 | Similar to NSEC, but hides zone contents |
| CDS | Child Delegation Signer (automation) |
| CDNSKEY | Child DNSKEY (automation) |
DNSSEC Validation
When a resolver receives a DNS response, it performs validation.
Steps:
- Retrieve the requested DNS record.
- Retrieve its RRSIG record.
- Retrieve the DNSKEY.
- Verify the signature.
- Verify the chain of trust up to the root zone.
If validation succeeds, the response is accepted.
Otherwise the resolver returns an error.
DNSSEC Does NOT Encrypt DNS
A common misconception is that DNSSEC encrypts DNS traffic.
It does not.
DNSSEC provides:
- Authentication
- Integrity
It does not provide:
- Confidentiality
- Privacy
- Encryption
DNS queries remain visible on the network.
For encrypted DNS, technologies such as DNS over HTTPS (DoH) and DNS over TLS (DoT) are used.
DNSSEC vs DoH vs DoT
| Technology | Authentication | Encryption |
|---|---|---|
| DNS | No | No |
| DNSSEC | Yes | No |
| DNS over TLS (DoT) | No | Yes |
| DNS over HTTPS (DoH) | No | Yes |
| DNSSEC + DoH | Yes | Yes |
DNSSEC and DoH solve different security problems and are often used together.
Advantages
DNSSEC provides:
- Protection against cache poisoning
- Protection against forged DNS responses
- Verification that DNS records originate from the authoritative server
- Increased trust in DNS infrastructure
Limitations
DNSSEC does not:
- Hide DNS queries.
- Encrypt DNS traffic.
- Prevent DDoS attacks.
- Protect websites against compromise.
It only verifies the authenticity of DNS data.
How Can I Check Whether a Domain Uses DNSSEC?
A domain usually supports DNSSEC if:
- A DS record exists in the parent zone.
- The zone publishes DNSKEY records.
- DNS responses contain RRSIG records.
Example:
example.com DNSKEY RRSIG DS
DNSSEC and Telenegar
Telenegar DNS Check can help determine whether a domain supports DNSSEC by:
- Querying DNSSEC-related record types.
- Displaying DNSKEY records.
- Displaying DS records.
- Displaying RRSIG records.
- Indicating whether DNSSEC appears to be enabled.
Future versions may also perform DNSSEC validation.
Common Misconceptions
- DNSSEC encrypts DNS traffic.
- False. DNSSEC only authenticates DNS data.
- DNSSEC prevents every DNS attack.
- False. It prevents forged DNS responses but not every attack.
- DoH replaces DNSSEC.
- False. DNSSEC and DoH provide different security properties.
Related Topics
dns dnssec dnskey ds rrsig nsec doh dot security
