Classic DNS has no way to prove that an answer is genuine, so attackers who can inject forged responses (cache poisoning or spoofing) can redirect users to malicious servers. DNS Security Extensions (DNSSEC) fix this by adding digital signatures to zone data. A resolver that validates DNSSEC can confirm that an answer really came from the zone's owner and was not altered, and can prove that a name does not exist. DNSSEC does not encrypt queries; it provides authenticity and integrity.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.