HomeGuidesDNSSEC at the root
DNS & protocol

DNSSEC at the root

What root-zone DS records mean, how the chain of trust reaches a TLD, and exactly what a static reference site can claim from that data.

On this page
TL;DR

DNSSEC adds cryptographic validation to DNS. A DS record for a TLD in the root is the parent-side link used to authenticate that TLD's DNSSEC chain. DS presence is a technical fact; it does not mean every domain beneath the TLD is signed.

The chain of trust

DNSSEC allows DNS data to be validated using digital signatures. Validation follows a chain of trust from a configured trust anchor through signed delegations toward the name being queried.

Simplified DNSSEC chain
Root trust anchorValidator's starting point
DS for .tld in rootParent-side delegation signer
TLD DNSKEYAuthenticates signed TLD data

What a DS record says

A DS record is published by the parent zone and identifies a key in the child zone. For a TLD, the parent is the DNS root. Its presence can therefore be used as a deterministic signal that the root contains a DNSSEC delegation for that TLD.

What it does not say

Root DS presence does not prove that every second-level domain beneath the TLD is signed, nor does it measure the operational quality of the TLD's DNS.

Avoid the “secure TLD” label

DNSSEC is one protocol property. It should not be turned into a broad security or trustworthiness rating.

How to display it

A reference page can show DS present, list the DS parameters published in the root, and link to the authoritative source. Anything more evaluative needs separate evidence.

Primary sources

These are the primary references this guide is designed around. When implementation data disagrees with editorial copy, the primary source wins.