Glossary · Security and privacy
DNSSEC
Signatures over DNS records, chained from the root through the registry to the zone, so that a resolver can detect a forged answer. It protects the lookup, not the site: a signed zone can still point at a compromised server.
What DNSSEC means
Signatures over DNS records, chained from the root through the registry to the zone, so that a resolver can detect a forged answer. It protects the lookup, not the site: a signed zone can still point at a compromised server. It is switched on at the DNS host and completed at the registrar, and a broken chain makes the domain unreachable.
What DNSSEC can and cannot support
| It can support | It cannot support |
|---|---|
| Signatures over DNS records, chained from the root through the registry to the zone, so that a resolver can detect a forged answer. It is switched on at the DNS host and completed at the registrar, and a broken chain makes the domain unreachable. | It protects the lookup, not the site: a signed zone can still point at a compromised server. |
Related terms in Security and privacy
Where an agent, a tool or a page can be turned against its operator, and the controls that limit the damage without proving safety.
Indirect prompt injection · Direct prompt injection · Jailbreak · Data exfiltration · Sensitive information disclosure · Secret leakage · Insecure output handling · Excessive agency · Least privilege · Trust boundary · Input validation · Output validation · Allowlist · Denylist · SSRF · RCE · Credential scope · OAuth scope · API key · Bearer token · mTLS · Rate-limit policy · Audit log · PII · Data minimization · Purpose limitation · Retention period · Data residency · Tenant isolation · Threat model · DMARC · DMARC alignment · SPF · DKIM · MTA-STS · TLS-RPT · CAA record · hard bounce
Questions about DNSSEC
What is DNSSEC?
Signatures over DNS records, chained from the root through the registry to the zone, so that a resolver can detect a forged answer. It protects the lookup, not the site: a signed zone can still point at a compromised server.
What does DNSSEC not show or guarantee?
It protects the lookup, not the site: a signed zone can still point at a compromised server.
Which area of the glossary does DNSSEC belong to?
Security and privacy: Where an agent, a tool or a page can be turned against its operator, and the controls that limit the damage without proving safety.
← CAA record · hard bounce →
See it in the full glossary · 668 terms across 19 areas.