A number of DNS zones have been enhanced with security, which lets my site verify that DNS records are really correct. For example, suppose a user looks up www.irs.gov in the DNS. Without DNS security (DNSSEC), someone could provide a forged DNS reply that provides a false IP address for the site. With DNSSEC, you can authenticate the DNS response and verify that you’re really getting the correct address. Do DNS caching resolvers support DNSSEC, and if so, how can you set up your DNS caching resolver so it provides this added security?
Topics: Security














