Back to blog
dns Published: AEU DNS Newsroom

Bangladesh's .bd Country Domain Moves From DNSSEC Workshop to Live Deployment

A reader asks about RDAP support, DNSSEC timing, and updating whois records after Bangladesh's .bd ccTLD moved from DNSSEC workshop to deployment.

Bangladesh's country-code top-level domain, .bd, has reached an important security milestone. According to a recent APNIC blog post, the .bd domain has moved from a DNSSEC workshop to actual deployment. DNSSEC, short for Domain Name System Security Extensions, is a set of checks that prove the internet's address book has not been tampered with. For a country like Bangladesh, this is a major step toward protecting website owners and visitors from impersonation and fraud. However, a reader comment on the post reveals that some practical questions remain unanswered: whether the .bd registry will offer RDAP, when DNSSEC will be fully implemented for all .bd domains, and how domain holders can update their whois information.

In simple terms, the Domain Name System (DNS) translates human-friendly names like example.bd into the numeric IP addresses that computers use to connect. Normally, that translation is sent without any proof of authenticity, which allows attackers to hijack a request and send a user to a fake website. DNSSEC adds digital signatures to DNS records. When a DNS resolver receives a signed answer, it can check the signature against a chain of trust that starts at the root of the DNS. If the signature is valid, the answer is authentic. For Bangladesh's .bd domain, deploying DNSSEC means that the registry is now signing the zone file for .bd, which lets domain owners publish their own DNSSEC records and lets internet users worldwide verify that a .bd website is the real one. The workshop-to-deployment progress shows that Bangladesh's technical community has moved from training to real-world operation, but the reader's question about timing suggests that some users still do not see DNSSEC working on their own domains.

The reader also asks whether RDAP will be implemented for .bd. RDAP stands for Registration Data Access Protocol. It is a modern replacement for the older whois system that has been used for decades to look up who owns a domain name, when it expires, and which registrar manages it. Traditional whois returns plain text over an unencrypted connection, which creates privacy and reliability problems. RDAP, by contrast, returns structured data in a standard format, can be accessed over encrypted HTTPS, and supports better access control and internationalization. Many country-code top-level domains such as .bd have been slow to deploy RDAP because it requires changes to the registry's back-end systems. The question is timely: as more registries around the world move to RDAP, users expect a consistent, secure way to query registration data. Without RDAP, .bd domain lookups remain stuck with the limitations of whois, including a lack of standardized privacy protections.

Finally, the reader asks whether there is any way to change whois information for .bd domains. Whois records contain the name, organization, email address, and other contact details of a domain registrant. Keeping these details accurate is important for proving ownership, receiving renewal reminders, and responding to abuse complaints. For most top-level domains, registrants make these changes through the registrar or reseller from whom they bought the domain. Because the blog post and reader comment do not specify the registry's policy for .bd, the general answer is that .bd domain holders should contact their domain registrar to update contact details. If the .bd registry has introduced a self-service portal, users may be able to update information directly, but the source does not confirm this. The fact that the reader asks about it suggests that the process may not be well documented or easily accessible.

For website owners, businesses, and everyday internet users in Bangladesh and beyond, these details matter. DNSSEC protects against domain hijacking and cache poisoning, which are attacks that can silently redirect visitors to fraudulent pages. RDAP and accurate whois data support accountability and trust in the domain registration system. While the APNIC blog post celebrates progress on DNSSEC, the unanswered questions show that operational deployments often raise new practical concerns. One step that every internet user can take right now is to choose a DNS resolver that validates DNSSEC signatures. AEU DNS, a privacy-first encrypted DNS service, performs DNSSEC validation on every query, so if a .bd website's signature does not match, the resolver will not return a forged answer. This adds an important layer of protection for anyone browsing the web, especially when visiting domains that have recently deployed DNSSEC.

Terms explained

DNSSEC
Domain Name System Security Extensions, a security check that adds digital signatures to internet address book records so you can be sure a website address is genuine.
ccTLD
Country code top-level domain, the two-letter internet suffix for a specific country or territory, such as .bd for Bangladesh.
RDAP
Registration Data Access Protocol, a modern, encrypted way to look up who owns a domain name, replacing the older whois system.
Whois
A public directory that shows the contact and technical details of a domain name registrant.
DNS resolver
A server that takes a website name you type and finds the corresponding numeric internet address, like a phone book for the internet.
Encrypted DNS
A way of sending your internet address lookups over a secure, private connection so others cannot see or alter them.

How to protect yourself

  1. If you own a .bd website address, ask the company where you bought it to turn on the security feature called DNSSEC, which proves your site is genuine.
  2. Use a private internet address book service that checks DNSSEC signatures, such as AEU DNS, so fake website answers are blocked automatically.
  3. Keep your contact details for your website address up-to-date in your account with the company that sold you the domain, so you can prove ownership and get renewal notices.
  4. Ask your domain company whether a secure, modern lookup service (called RDAP) is available for your domain, and use that instead of the old whois directory when checking ownership.
  5. If you run a website, run a free online DNSSEC test to see if your security keys are set up correctly.

Source: blog.apnic.net

Get private, encrypted DNS