Bangladesh's .bd Country Domain Moves From DNSSEC Workshop to Live Deployment
A reader asks about RDAP support, DNSSEC timing, and updating whois records after Bangladesh's .bd ccTLD moved from DNSSEC workshop to deployment.
OARC 45 Hears Why Encrypting the DNS Resolver-to-Authoritative Hop Has Stalled
A new report from OARC 45 reveals that encrypted DNS between recursive resolvers and authoritative servers remains largely undeployed, with only 0.93% of domains supporting any encrypted transport, and explains why both…
New IRTF Draft Maps Trust Anchors and Manufacturer-Installed Keys for Smarter Device Security
An IRTF draft now in its 14th iteration offers a taxonomy for understanding how trust is built into IoT devices, from factory-installed keys to the global DNSSEC trust anchor.
NIST Revises Secure DNS Guide, Treating DNS as a Security and Resilience Control
New NIST guidance moves DNS from background infrastructure to an active security control, covering protective DNS, DNSSEC validation, encrypted protocols, and logging for operators.
Hundreds of Queries for One Domain: The Hidden Work Behind a Cold Start DNS Lookup
A fresh look at what happens when a DNS resolver boots with an empty cache reveals why some names demand dozens or even hundreds of queries, and how resolver design balances speed against resilience.
Is DNS Resolution Becoming Too Centralized? New Measurements Paint a Mixed Picture
A new APNIC analysis examines concentration in DNS name registration and resolution markets, revealing a fragmented registrar landscape but a potential concentration of recursive resolver usage.
Securing the DNS Root: Testing Six Naming Schemes and the Road to DNSSEC Protection
A recent measurement study evaluates six different naming strategies for the Internet’s root DNS servers, examining whether DNSSEC can be added to secure the essential bootstrapping process without breaking compatibility…
Massive DNS Query Duplication Found by APNIC, 38% of Queries Repeated Unnecessarily
A new study from APNIC Labs shows that over 38% of DNS queries are duplicates, with some regions exceeding 60%, highlighting a tragedy of the commons in the internet's naming system.
Beyond the surface: The three layers of DNS resilience that keep websites online
New research reveals the multi-layered infrastructure behind domain names and uncovers common weak spots in authoritative DNS setups, especially among government services.
