CrawlCheck

Glossary · Security and privacy

DNSSEC

Signatures over DNS records, chained from the root through the registry to the zone, so that a resolver can detect a forged answer. It protects the lookup, not the site: a signed zone can still point at a compromised server.

What DNSSEC means

Signatures over DNS records, chained from the root through the registry to the zone, so that a resolver can detect a forged answer. It protects the lookup, not the site: a signed zone can still point at a compromised server. It is switched on at the DNS host and completed at the registrar, and a broken chain makes the domain unreachable.

What DNSSEC can and cannot support

It can supportIt cannot support
Signatures over DNS records, chained from the root through the registry to the zone, so that a resolver can detect a forged answer. It is switched on at the DNS host and completed at the registrar, and a broken chain makes the domain unreachable.It protects the lookup, not the site: a signed zone can still point at a compromised server.

Related terms in Security and privacy

Where an agent, a tool or a page can be turned against its operator, and the controls that limit the damage without proving safety.

Indirect prompt injection · Direct prompt injection · Jailbreak · Data exfiltration · Sensitive information disclosure · Secret leakage · Insecure output handling · Excessive agency · Least privilege · Trust boundary · Input validation · Output validation · Allowlist · Denylist · SSRF · RCE · Credential scope · OAuth scope · API key · Bearer token · mTLS · Rate-limit policy · Audit log · PII · Data minimization · Purpose limitation · Retention period · Data residency · Tenant isolation · Threat model · DMARC · DMARC alignment · SPF · DKIM · MTA-STS · TLS-RPT · CAA record · hard bounce

Questions about DNSSEC

What is DNSSEC?

Signatures over DNS records, chained from the root through the registry to the zone, so that a resolver can detect a forged answer. It protects the lookup, not the site: a signed zone can still point at a compromised server.

What does DNSSEC not show or guarantee?

It protects the lookup, not the site: a signed zone can still point at a compromised server.

Which area of the glossary does DNSSEC belong to?

Security and privacy: Where an agent, a tool or a page can be turned against its operator, and the controls that limit the damage without proving safety.

← CAA record  ·  hard bounce →

See it in the full glossary · 668 terms across 19 areas.