Category: DNSSEC Validation

Plan – Where We Need To Get DNSSEC Validation Happening

For DNSSEC to succeed, we need to get DNSSEC validation happening within DNS resolvers at many different levels within the Internet ecosystem.  Ideally, the DNSSEC validation will occur as close as possible to the end user (either a person or a device) so that the attack surface where an attacker could inject bogus DNS packets is minimized.  For instance, if the DNSSEC validation occurs within an application on the end device, there is very little an attacker can do to inject bogus DNS packets.  On the other hand, if the DNSSEC validation occurs out at a public DNS server somewhere out on the Internet, the attacker can inject packets anywhere between that public DNS server and the end device.  The reality is that we would like to see DNSSEC validation happening at many different levels.

This page exists to track the progress of where we are with getting DNSSEC validation happening across the Internet.  It is organized from the farthest point away from the end device down to the closest.  

[At the moment, this page is a work-in-progress as we are still updating it with the current status of information (and feedback is welcome). ]

Public DNS Services

While the attack surface is quite large, it is still useful to have DNSSEC validation occurring in public DNS services available to all across the open Internet.  The list of services known to perform DNSSEC validation by default includes:

Internet Service Providers / Network Operators

Internet Service Providers (ISPs) and other network operators are an excellent  location for DNSSEC validation to occur as the ISPs DNS servers are typically provided to all customers as the “default” DNS resolvers for the customers to use.  Attacks are still possible if an attacker can get onto the ISPs network but the area of the attack is significantly less than the entire Internet.  Major ISPs known to support DNSSEC by default include:

  • Comcast (North America)
  • (list of ISPs in Sweden, Czech Republic, Netherlands, Brazil)

If you are an ISP or network operator and want to support DNSSEC validation, please see our page about DNSSEC for network operators.

Enterprise Networks

Enterprise networks are a critical place to perform DNSSEC validation as they can do so on behalf of a secured corporate network.

Suggestions for how to deploy DNSSEC validation can be found on our DNSSEC for enterprise customers page.

Home Networks and Consumer Electronic Devices (ex. home routers)

(include a list of consumer devices supporting DNSSEC validation – also include mention of dnsmasq)

Operating Systems

Having DNSSEC validation occur within the operating system of a device is one of the best places for validation to occur.  The following operating systems are known to have DNSSEC validation enabled by default:

It is certainly possible for an individual to configure DNSSEC validation on an individual system using tools such as:

There are also guides out there that explain the easy steps to enable validation on existing systems:

Applications

Ideally applications themselves may perform DNSSEC validation.

(include a list of applications known to include DNSSEC validation)

Resources available to developers include:

  • List of developer libraries supporting DNSSEC
  • getDNS API

More information can be found on the DNSSEC for developers page.