Glossary
DNSSEC
DNSSEC
A set of DNS extensions that sign zone data so a resolver can verify an answer came from the zone owner and was not modified. It provides authenticity and integrity — not confidentiality. DNSSEC does not encrypt anything.
Defined in RFC 4033–4035.
Where this appears
The lessons that use this term, and what each is for.
Advanced Email TrustTwo answers to the same problemSay what MTA-STS and DANE each assert, and which part of the trust they place elsewhere.Advanced Email TrustTLSA recordsRead a TLSA record field by field and say what a verifier will compare it against.Advanced Email TrustThe dependency that decides availabilityDetermine from DNS alone whether DANE is even possible for a given domain.Advanced Email TrustChoosing, or running bothDefend a choice between DANE and MTA-STS for a specific domain and receiver mix.Domain Security FundamentalsWhat DNSSEC protects againstSay what a signed zone proves and, precisely, what it does not.Domain Security FundamentalsWalking the chain of trustFollow a chain from the root to a zone and confirm each link yourself.DNS Security PractitionerOne key or twoRead a zone’s DNSKEY set and say which signing arrangement it uses and why.DNS Security PractitionerWhich algorithmChoose a signing algorithm for a new zone, and name what to migrate off.DNS Security PractitionerSignatures expireExplain why a zone that was valid yesterday fails today with no change made to it.DNS Security PractitionerNSEC enumerates your zoneWalk a zone using its own denial records, and say what that exposes.DNS Security PractitionerWhat NSEC3 fixed, and did notSay what NSEC3 hashing costs and why it did not end zone enumeration.DNS Security PractitionerAnswering on the flyExplain how a signer denies a name without ever listing the ones that exist.DNS Security PractitionerRolling the signing keyChoose between pre-publish and double-signature, and say what each costs.DNS Security PractitionerRunning twoSay what must stay synchronised across two providers, and what DNSSEC adds to that.Domain Trust ArchitectureA definition worth usingDefine domain trust in a way that does not depend on any product or vendor.Domain Trust ArchitectureThe four surfacesPlace any control on one of four surfaces, and say which surface a given attack targets.Domain Trust ArchitectureWhere each control sitsMap every control you have learned onto the surface it defends.Domain Trust ArchitectureThe dependency graphDraw what depends on what, and identify the controls that cannot be deployed yet.Domain Trust ArchitectureWhat must come firstSequence a programme so each step rests on something already working.Domain Trust ArchitectureA method you can run by handAssess any estate against every surface using public data and a fixed sequence.Domain Trust ArchitectureWhat a score cannot sayUse a posture score without letting it stand in for the assessment.Domain Trust ArchitectureImpact against effort, honestlyRank remediation without pretending either axis is more precise than it is.Domain Trust ArchitectureThe ones worth skippingDefend a decision not to deploy a control, in writing.Domain Trust ArchitectureWhat decays, and how fastGive each control a review cadence derived from how quickly it goes wrong.Domain Security PractitionerPosture, domain by domainProduce the assessment table for a mixed estate and rank every finding.Domain Security PractitionerA broken chain you cannot fixDecide what to do about a DNSSEC failure in a zone somebody else operates.Domain Security PractitionerNinety days, and a yearSequence the funded work around the constraints you cannot remove.Domain Security PractitionerThe listWrite the not-doing section for a specific estate, with triggers.Domain Security PractitionerDefending it afterwardsAnswer for an omission after an incident, when the omission was deliberate.