Back to blog
dns Published: AEU DNS Newsroom

Slow DNSSEC Uptake Highlights Need for Automation and a DNS Overhaul

Slow DNSSEC Uptake Highlights Need for Automation and a DNS Overhaul

A comment on DNSSEC automation reveals familiar friction: complex setup, low adoption, and calls to redesign the 1980s-era DNS. Industry best practices may hold the key.

A recent comment on an APNIC blog post titled "Towards an industry best practice for DNSSEC automation" captures a familiar frustration: despite years of standards work, DNSSEC remains hard to deploy. A practitioner writing under the name Bird noted that the slow uptake is not surprising, pointing to a similar pattern in IPv6 adoption. Even someone with basic DNS knowledge can find adding DNSSEC far from straightforward, which makes the low adoption both unfortunate and understandable. This sentiment highlights a core challenge for the internet's security infrastructure: protecting the domain name system is technically sound but operationally burdensome.

DNSSEC, short for Domain Name System Security Extensions, adds cryptographic signatures to DNS records. This lets resolvers verify that the answer they receive for a website address is authentic and has not been altered in transit. Without DNSSEC, attackers can potentially poison caches or spoof responses, redirecting users to malicious sites without their knowledge. Yet turning on DNSSEC typically means generating and managing cryptographic keys, signing zone data, and periodically rolling keys according to strict timing rules. Any mistake can make a domain unreachable, which is a powerful deterrent for administrators who might otherwise want the security benefit.

The commenter's comparison to IPv6 is telling. IPv6, the newer internet protocol with a vastly larger address space, was standardized decades ago but still lags behind older IPv4 in many networks. Both DNSSEC and IPv6 are better technologies that require coordinated changes across many independent operators, creating inertia. In the case of DNSSEC, the lack of simple automation is a key barrier. Instead of a manual, error-prone process, an industry best practice for automation would handle key generation, signing, and rollover automatically, reducing the risk of configuration errors and encouraging wider deployment. The APNIC post that drew the comment explicitly aims at such a best practice, reflecting a growing consensus that automation is the missing piece.

Bird also suggests a more radical path: overhauling the entire DNS. Noting that the current system was designed in the 1980s, the commenter believes a redesigned DNS could improve caching, reduce server load, and eliminate some major security gaps while keeping its decentralized nature. The question "Who should i talk to if i wanted to propose a concept?" underscores the difficulty of engaging with the internet's distributed governance and standards bodies. While a full replacement of DNS is far beyond the near-term horizon, the underlying concern about legacy design is shared by many security practitioners who see incremental improvements like DNSSEC automation as a pragmatic first step.

For website owners, businesses, and IT teams, the practical takeaway is clear. Even if you do not run your own DNS servers, the security of the resolver you use matters. A resolver that validates DNSSEC signatures will reject forged answers, adding a meaningful layer of protection against phishing and redirection attacks. Many managed DNS providers now offer one-click DNSSEC signing, but checking that option and verifying it works correctly is still your responsibility. Automation cannot come soon enough for the long tail of smaller operators who lack specialized DNS expertise. Choosing a private, encrypted DNS service such as AEU DNS gives users a resolver that prioritises security, which can reduce the impact of tampering while the broader DNSSEC ecosystem matures.

Terms explained

DNSSEC
Domain Name System Security Extensions, a security layer that adds digital signatures to website address records so computers can verify they are authentic.
DNS
The internet's phonebook that matches website names to numeric addresses computers use.
resolver
A server that looks up website addresses for you when you type a name into a browser.
caching
Temporarily storing recently looked-up website addresses to make future visits faster and reduce load on servers.
IPv6
The newer internet protocol with a much larger number of possible device addresses, still being adopted slowly.
zone
A group of DNS records for one domain name and its subdomains managed together.

How to protect yourself

  1. If you manage a website domain, log in to your DNS provider or registrar and look for a DNSSEC or Domain Name System Security option; if available, turn it on with one click.
  2. Use a secure DNS resolver that checks DNSSEC signatures, such as a privacy-focused public resolver, on your computer or router to automatically block fake website addresses.
  3. Turn on two-factor authentication (a second login step, like a code from your phone) for your domain registrar and DNS provider accounts so attackers cannot change your website's address records.
  4. After enabling DNSSEC, run a free online DNSSEC test to confirm your domain's security settings are correct and do not break your website.
  5. Ask your DNS hosting provider if they support automatic DNSSEC key management; if not, request it or consider a provider that does to avoid manual setup mistakes.

Source: blog.apnic.net

Get private, encrypted DNS