DNSSEC via RDAP

DNSSEC via RDAP is source-specific public evidence copied from the RDAP secureDNS.delegationSigned assertion where available.

Observed evidenceDNSSECRDAP-side source

What .auDO observes

The public registration-side DNSSEC assertion

.auDO records the value exposed through RDAP without treating it as a derived posture conclusion. The assertion is compared with DNS-side evidence in the combined DNSSEC posture view.

Technical fields

dnssec_enabled_rdaprdap_raw.secureDNS.delegationSigneddns_raw.dnssec_enabled_rdapdnssec_mismatch

Why it is observed

A second source helps explain assertion consistency

Why it matters

The RDAP assertion provides registration-side evidence that can be compared with direct DNSKEY visibility.

What visible change may mean

A change may reflect registrar or registry updates, delegation processing, provider migration, source representation, timing or fallback collection.

Interpretation limits

A source assertion is not end-to-end validation

Absence from RDAP does not necessarily establish that DNSSEC is absent. The assertion should be compared with direct DNS evidence and source-availability context.

Common retained observations

DNSSEC visibility and assertion-gap movement

DNSSEC visibility changeDNSSEC assertion gap change

Where to use this evidence

Read the assertion within combined posture

Related concept

How DNSSEC works