---
tags:
- networking
- l1
- flashcard-deck
- dnssec
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [DNSSEC & DNS Security](../../../../library/portal/topics.md) | **Domain:** Networking
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
dnssec/a1b2c3d4e5f6	dnssec	easy	dnssec,security,dns	What is DNSSEC and what problem does it solve?	DNSSEC (DNS Security Extensions) adds cryptographic signatures to DNS records, allowing resolvers to verify that responses have not been tampered with. It prevents DNS spoofing/cache poisoning attacks where an attacker returns forged DNS responses to redirect traffic to malicious servers.	training/library/topics/dnssec/primer.md
dnssec/b2c3d4e5f6a7	dnssec	medium	dnssec,chain-of-trust	How does the DNSSEC chain of trust work?	The root zone signs the TLD zone's key (DS record), the TLD signs the domain's key, and the domain signs its records. Each level vouches for the next via DS (Delegation Signer) records. The root trust anchor is built into resolvers. If any link in the chain is broken or expired, validation fails.	training/library/topics/dnssec/primer.md
dnssec/c3d4e5f6a7b8	dnssec	medium	dnssec,records	What are the key DNSSEC record types?	RRSIG: cryptographic signature for a record set. DNSKEY: public key used to verify RRSIG. DS: hash of child zone's DNSKEY stored in parent zone (the trust link). NSEC/NSEC3: proves a record does NOT exist (authenticated denial of existence). These records are added alongside normal DNS records.	training/library/topics/dnssec/primer.md
dnssec/d4e5f6a7b8c9	dnssec	hard	dnssec,key-management	What is the difference between KSK and ZSK?	KSK (Key Signing Key) signs the DNSKEY record set and is referenced by the parent zone's DS record. It is rolled infrequently (yearly) because changing it requires updating the parent. ZSK (Zone Signing Key) signs all other record sets and is rolled more frequently (monthly/quarterly). Separating them limits the blast radius of key compromise.	training/library/topics/dnssec/primer.md
dnssec/e5f6a7b8c9d0	dnssec	easy	dnssec,validation	How do you check if a domain has DNSSEC enabled?	dig +dnssec <domain> — look for RRSIG records in the response and the ad (Authenticated Data) flag. dig DS <domain> @parent-ns — check for DS records in the parent zone. Online tools: dnsviz.net visualizes the chain of trust. delv <domain> provides detailed validation results.	training/library/topics/dnssec/primer.md
dnssec/f6a7b8c9d0e1	dnssec	hard	dnssec,troubleshooting	What are common DNSSEC failure modes?	1) Expired signatures (RRSIG past validity period) — most common, caused by failed re-signing. \n2) Missing DS record in parent zone after key rollover. \n3) Algorithm mismatch between DNSKEY and RRSIG. \n4) Clock skew on resolvers (signatures are time-bound). \n5) NSEC walking exposing zone contents (use NSEC3 to mitigate).	training/library/topics/dnssec/primer.md
dnssec/a7b8c9d0e1f2	dnssec	medium	dnssec,deployment	What are the challenges of deploying DNSSEC?	1) Key management complexity (rotation, emergency rollover). \n2) Larger DNS responses (signatures add bytes, may exceed UDP 512 limit — requires EDNS0). \n3) Zone walking with NSEC reveals all records. \n4) Operational risk — misconfigurations make the domain unreachable for validating resolvers. \n5) Not all registrars support DS record management.	training/library/topics/dnssec/primer.md
dnssec/b8c9d0e1f2a3	dnssec	medium	dnssec,nsec3	What is NSEC3 and why was it introduced?	NSEC (Next Secure) proves a record does not exist but allows "zone walking" — enumerating all records by following NSEC chains. NSEC3 replaces plaintext names with hashed names, preventing enumeration while still proving non-existence. NSEC3 adds computational overhead and complexity but is standard practice for zones that want to prevent reconnaissance.	training/library/topics/dnssec/primer.md
dnssec/c9d0e1f2a3b4	dnssec	hard	dnssec,keyrollover	How do you perform a DNSSEC key rollover safely?	For ZSK: pre-publish the new key, wait for TTL, start signing with new key, remove old key. For KSK: publish new DNSKEY, submit new DS to parent registrar, wait for parent propagation, remove old DNSKEY. Always overlap old and new keys during transition. Automated tools: BIND dnssec-keymgr, Knot KASP, or cloud-managed DNSSEC handles this automatically.	training/library/topics/dnssec/primer.md
dnssec/d0e1f2a3b4c5	dnssec	easy	dnssec,adoption	What percentage of domains use DNSSEC and why isn't adoption higher?	As of 2025, roughly 30% of .com domains are signed, but validation-enabled resolvers cover ~30% of global queries. Adoption is low because DNSSEC adds operational complexity, misconfigurations cause outages, many registrars make it hard to manage DS records, and alternative solutions like DNS-over-HTTPS/TLS address some (but not all) of the same threats.	training/library/topics/dnssec/primer.md

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [DNSSEC & DNS Security](../../../../library/topics/dnssec/index.md) (Topic Pack, L2) — DNSSEC & DNS Security

<!-- wiki:related:end -->
