What is DNSSEC, and why isn't it everywhere?
DNSSEC adds cryptographic signatures to DNS records so a resolver can verify that an answer genuinely came from the domain's owner and was not altered in transit. It addresses a real weakness, and its adoption has been slow for reasons worth understanding.
The problem. Ordinary DNS is unauthenticated. A resolver receiving an answer has no way to confirm it is genuine. Cache poisoning attacks exploit this — injecting a forged response so that a resolver, and everyone using it, is sent to an attacker's server for a legitimate domain name.
How DNSSEC works. Each zone signs its records with a private key and publishes the corresponding public key. A chain of trust runs down the DNS hierarchy: the root zone signs for the top-level domains, each TLD signs for its delegations, and each domain signs its own records. A resolver validates each link back to the root key, which it trusts implicitly.
The root zone was signed in 2010, and the ceremonies at which the root key is managed are conducted publicly with multiple witnesses — one of the more unusual governance arrangements in technology.
What DNSSEC does and does not do:
It provides authenticity and integrity — this answer came from the zone owner and was not modified.
It does not provide confidentiality. Queries and answers remain in plain text and fully visible. DNSSEC and DNS over HTTPS solve different problems and are complementary, not alternatives — a point routinely confused.
Why adoption lags:
Operational fragility. Signatures expire. A domain whose signatures lapse or whose keys are rolled incorrectly becomes unreachable for validating resolvers — a harder failure than the problem it prevents. Several large outages have been caused this way, which makes operators cautious.
Key rollover is genuinely complex, and the delegation record must be updated at the registrar in step with the zone.
Incomplete benefit without validation. Signing a domain achieves nothing unless resolvers validate — and many do, but not all.
Zone enumeration concerns, partially addressed by later record types.
Where it is well established: many country TLDs mandate or incentivise it, and adoption is high in some regions and low in others.