What DNSSEC does
DNSSEC provides a method where resolvers can reliably affirm that the responses they've received to their lookup queries are unaltered, and that the DNS lookup chain used to arrive at the authoritative name server for a given query can be trusted (trust chain).
Without this mechanism, it is possible that a response received to a query has been altered in transit, and that can have big implications.
For example, when you enter the URL for your online banking, or your cryptocurrency wallet in your web browser, it is highly desirable to know that the IP address you are connecting to after the DNS lookup is the actual IP address for your bank's web portal or the actual cryptocurrency exchange.
A more common example of an everyday ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access