Men and Mice

spain france german china



Domain Name System Security Extensions (DNSSEC)


What is DNSSEC?

DNSSEC (short for DNS Security Extensions) adds security to the Domain Name System.

The original design of the Domain Name System (DNS) did not include security; instead it was designed to be a scalable distributed system. The Domain Name System Security Extensions (DNSSEC) attempts to add security, while maintaining backwards compatibility.

DNSSEC was designed to protect Internet resolvers (clients) from forged DNS data, such as that created by DNS cache poisoning. It is a set of extensions to DNS, which provide to DNS clients (resolvers):

    a) origin authentication of DNS data
    b) data integrity (but not availability or confidentiality)
    c) authenticated denial of existence.

All answers in DNSSEC are digitally signed. By checking the digital signature, a DNS resolver is able to check if the information is identical (correct and complete) to the information on the authoritative DNS server. While protecting IP addresses is the immediate concern for many users, DNSSEC can protect other information such as general-purpose cryptographic certificates stored in CERT records in the DNS.

Having been through difficulties in development over the years, the DNSSEC protocol has been improved up to the point that it is now widely accepted in its current incarnation. With the signing of the root zone in 2010 and the signing of the .com zone in 2011 the speed of DNSSEC adoption is expected to increase rapidly in the coming years.

The Men & Mice Suite can be integrated with some of the most commonly used tools to sign DNSSEC zones today. This should enable you to do the most common DNS management tasks in much the same way as before, enhancing your DNS security without overly increasing the complexity.


Click here to
Try the Men & Mice Suite

or contact our support team, which can assist and consult you in the deployment of DNSSEC at your organization.


How does DNSSEC work?

What are some of the benefits of DNSSEC?

How to deploy DNSSEC?

Where to learn more about DNSSEC?