User Tools

Site Tools


networking:dnssec

This is an old revision of the document!


DNSSEC Explained

DNS Security Extensions (DNSSEC) is a set of extensions to the Domain Name System (DNS) that allows DNS responses to be cryptographically verified.

DNSSEC helps ensure that DNS records have not been modified or forged while they travel across the Internet.

DNSSEC provides:

  • Data authenticity
  • Data integrity
  • Protection against DNS spoofing and cache poisoning

DNSSEC does not provide encryption or privacy.


Why Was DNSSEC Created?

Traditional DNS was designed without security.

An attacker may attempt to convince a recursive resolver that a fake IP address belongs to a domain.

Example:

Attacker

example.com
        │
        ▼

203.0.113.200  (Fake)

instead of

93.184.216.34

If the resolver accepts the forged response, users may be redirected to a malicious website.

DNSSEC prevents this by allowing DNS responses to be digitally signed.


How DNSSEC Works

Each DNS zone has a pair of cryptographic keys.

  • Private Key
  • Public Key

The authoritative DNS server signs its DNS records using the private key.

Resolvers verify the signatures using the corresponding public key.

Authoritative Server

DNS Record
      │
      ▼
Digital Signature
      │
      ▼
Recursive Resolver
      │
Verify Signature
      │
      ▼
Trusted Answer

If verification fails, the resolver rejects the response.


Chain of Trust

DNSSEC works through a chain of trust.

Each level of the DNS hierarchy signs the next level.

Root Zone
     │
     ▼
.com
     │
     ▼
example.com

The root zone is the trust anchor for the entire DNSSEC system.

If every signature is valid, the resolver can trust the final DNS record.


DNSSEC Record Types

DNSSEC introduces several additional DNS record types.

Record Purpose
DNSKEY Public key for the DNS zone
DS Delegation Signer (links parent and child zones)
RRSIG Digital signature for DNS records
NSEC Authenticated proof that a record does not exist
NSEC3 Similar to NSEC, but hides zone contents
CDS Child Delegation Signer (automation)
CDNSKEY Child DNSKEY (automation)

DNSSEC Validation

When a resolver receives a DNS response, it performs validation.

Steps:

  1. Retrieve the requested DNS record.
  2. Retrieve its RRSIG record.
  3. Retrieve the DNSKEY.
  4. Verify the signature.
  5. Verify the chain of trust up to the root zone.

If validation succeeds, the response is accepted.

Otherwise the resolver returns an error.


DNSSEC Does NOT Encrypt DNS

A common misconception is that DNSSEC encrypts DNS traffic.

It does not.

DNSSEC provides:

  • Authentication
  • Integrity

It does not provide:

  • Confidentiality
  • Privacy
  • Encryption

DNS queries remain visible on the network.

For encrypted DNS, technologies such as DNS over HTTPS (DoH) and DNS over TLS (DoT) are used.


DNSSEC vs DoH vs DoT

Technology Authentication Encryption
DNS No No
DNSSEC Yes No
DNS over TLS (DoT) No Yes
DNS over HTTPS (DoH) No Yes
DNSSEC + DoH Yes Yes

DNSSEC and DoH solve different security problems and are often used together.


Advantages

DNSSEC provides:

  • Protection against cache poisoning
  • Protection against forged DNS responses
  • Verification that DNS records originate from the authoritative server
  • Increased trust in DNS infrastructure

Limitations

DNSSEC does not:

  • Hide DNS queries.
  • Encrypt DNS traffic.
  • Prevent DDoS attacks.
  • Protect websites against compromise.

It only verifies the authenticity of DNS data.


How Can I Check Whether a Domain Uses DNSSEC?

A domain usually supports DNSSEC if:

  • A DS record exists in the parent zone.
  • The zone publishes DNSKEY records.
  • DNS responses contain RRSIG records.

Example:

example.com

DNSKEY
RRSIG
DS

DNSSEC and Telenegar

Telenegar DNS Check can help determine whether a domain supports DNSSEC by:

  • Querying DNSSEC-related record types.
  • Displaying DNSKEY records.
  • Displaying DS records.
  • Displaying RRSIG records.
  • Indicating whether DNSSEC appears to be enabled.

Future versions may also perform DNSSEC validation.


Common Misconceptions

  • DNSSEC encrypts DNS traffic.
    • False. DNSSEC only authenticates DNS data.
  • DNSSEC prevents every DNS attack.
    • False. It prevents forged DNS responses but not every attack.
  • DoH replaces DNSSEC.
    • False. DNSSEC and DoH provide different security properties.


dns dnssec dnskey ds rrsig nsec doh dot security

networking/dnssec.1784734546.txt.gz · Last modified: by 127.0.0.1 · Currently locked by: 216.73.217.88