A set of DNS extensions that add digital signatures to records, letting resolvers confirm a response is authentic rather than forged. Zones hosted in Azure Public DNS support signing.
Also called Domain Name System Security Extensions.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains DNSSEC in context, with comparison tables and the common traps.
Terms in this definition
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- DNS
The system that turns names into addresses. In Azure, private endpoints depend on private DNS zones, which are queried through 168.63.129.16.
- Architecture Definition Document
A key deliverable bringing together the main architecture artifacts across the four domains for every relevant state: baseline, transition and target. It sets out, in qualitative terms, what the architect intends.
- Azure Public DNS
Hosting for the public zone of an internet domain you own, managed with your normal Azure tools, credentials and billing. Domain names can't be purchased through it.
Related terms
- DNSKEY
In DNSSEC, the record type a signed zone uses to publish its public keys, for instance the KSK or ZSK.
- NRPT
Name Resolution Policy Table. Typically pushed out with Group Policy, it holds rules per namespace that either demand DNSSEC validation or direct lookups to chosen DNS servers.
- NSEC
A DNSSEC record providing proof that a name is absent. It makes zone walking possible, something NSEC3 was designed to stop.
- NSEC3
The DNSSEC successor to NSEC that proves a name is absent using hashed names, so the zone can't be walked. Its settings live in the NSEC3PARAM record, and any zone uses either NSEC or NSEC3 but never both.
- RRSIG
A signature record in DNSSEC; one covers every record that shares both a name and a record type.
- SERVFAIL
Returned by a DNS server that failed to handle a request, perhaps because DNSSEC validation failed or an upstream server never replied.
- SHA-256
A SHA-2 hash algorithm, used for instance when signing DNSSEC zones (RSA/SHA-256 being the default) and for certificate thumbprints.
- Trust anchor
A public key configured in advance, for example a DS or DNSKEY record, from which a validating resolver begins checking DNSSEC signatures.