In DNSSEC, the record type a signed zone uses to publish its public keys, for instance the KSK or ZSK.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains DNSKEY in context, with comparison tables and the common traps.
Terms in this definition
- DNSSEC
A set of DNS extensions that add digital signatures to records, letting resolvers confirm a response is authentic rather than forged. Zones hosted in Azure Public DNS support signing.
- KSK
Key signing key: signs the DNSKEY records of a zone, and its public half is what parent zones' DS records and trust anchors point to.
- ZSK
The zone signing key signs a zone's records under DNSSEC, while the key signing key signs the DNSKEY records themselves.
Related terms
- Trust anchor
A public key configured in advance, for example a DS or DNSKEY record, from which a validating resolver begins checking DNSSEC signatures.