DNSSEC posture

DNSSEC posture is a combined interpretation of public DNSKEY evidence and source-specific RDAP DNSSEC assertions where available.

Derived postureDNSSECMultiple evidence sources

What .auDO derives

A combined posture from distinct public assertions

.auDO compares directly observed DNSKEY presence with the public RDAP secureDNS.delegationSigned assertion where available. The combined page is the posture reference; the supporting source pages remain inspectable separately.

Technical fields

dnssec_enableddnssec_enabled_rdapdnskey_presentdnssec_mismatch

Why it is derived

Comparing sources makes visible posture more explainable

Why it matters

DNSSEC can provide cryptographic assurance for DNS responses when correctly configured. Comparing visible assertions helps preserve posture and source-consistency evidence over time.

What visible change may mean

A change may reflect rollout, key publication, delegation updates, registrar or registry processing, provider migration, source timing or maintenance.

Interpretation limits

Visible posture is not end-to-end validation

Presence alone does not establish a valid chain for every resolver or complete operational quality. A source assertion gap may reflect timing, collection or representation differences.

Common retained observations

DNSSEC posture and assertion-gap movement

DNSSEC visibility changeDNSSEC assertion gap change

Where to use this evidence

View current DNSSEC posture and movement

Related concept

How DNSSEC works

Supporting evidence