All checks

DNSSEC

DNSSEC records proving DNS answers have not been tampered with

What it is

Plain DNS gives a client no way to tell a genuine answer from a forged one, which is what makes cache poisoning and on-path spoofing possible. DNSSEC signs records with public-key cryptography so a resolver can verify nothing was altered along the way. DoH and DoT address a different half of the problem by encrypting the query itself.

Why it matters

Whether a zone is signed says something about how carefully its DNS is run. An unsigned zone is not a vulnerability on its own, but it removes one defence against an attacker already in a position to interfere with resolution.

Related checks