Skip to content
A chain of trust running from the signed root through a signed TLD and stopping at an unsigned second-level domain, with the counted figures beside each step

DNSSEC: Protecting Your Traffic From Forgery

The hard part of DNSSEC was finished years ago. Counted from the live root zone on 27 September 2026, 1,351 of 1,438 top level domains carry a DS record and every one of the 1,038 gTLDs is signed. Then it stops dead. A census of every gov.uk domain in the official register finds 39 signed out of 2,390 that still resolve, nine of them parish councils, while HMRC, the NHS, GCHQ and the National Cyber Security Centre are not among them. One certificate authority in nine has signed. So has one Linux distribution in three. windowsupdate.com has no DS at all. This is what a forged answer actually costs, what signing does about it, why the usual excuses do not survive contact with the numbers, and whether forty-two years after Mockapetris the real problem is that almost nobody understands what DNS actually promises.

27th September 2026 Â· 48 min Â· 10979 words Â· Damien Dye
A name lookup passing through systemd-resolved's stub listener into a cache, a validator and an encrypted transport, with the validator and the encryption switched off

Resolved: The Resolver You Are Already Running

systemd-resolved is running on most Linux desktops right now, caching every lookup and validating none of them. This walks the resolution path from nss-resolve to the two stub listeners, measures what the cache is worth on a real machine, turns DNSSEC on and shows the three verdicts it can return, and explains why validation is off by default when upstream ships it on. Then a census of how little of the web is actually signed, DNS over TLS and its strict-versus-opportunistic trap, and the DNS over HTTPS support that has been requested since 2018 and still does not exist. Ends with what Fedora, Ubuntu, Debian and the RHEL family each ship, how to wire it into each one, and why the features your distro disabled are defaults rather than missing code.

27th September 2026 Â· 38 min Â· 8443 words Â· Damien Dye

Who Actually Controls DNS

The root of the internet is a 1.5 MB text file that one American company edits and signs. Who really controls DNS, what the 2016 IANA transition did and did not change, and the documented record of how ICANN has used that control.

25th August 2026 Â· 50 min Â· 10443 words Â· Damien Dye
A delegation chain from the root down to an internal Active Directory zone, with client writes confined to a separate sub-zone

Samba4 and Securing AD Records Using DNSSEC

Every domain-joined machine finds its domain controller by asking DNS for an SRV record, so the _msdcs locators are the most security-critical records you own. This is how to publish and sign them properly from a Samba4 DC: BIND with dlz_bind9 reading the directory, inline signing, a hidden primary that clients never reach, and client dynamic updates kept out of the zone that holds the locators. Then how to force Windows and Linux clients to actually check the signatures, because a signed zone nobody validates behaves exactly like an unsigned one.

24th August 2026 Â· 65 min Â· 13681 words Â· Damien Dye