we_are_coded.by CODE · The world, decoded
БГ
Concept

DNS and DNSSEC (the internet's directory and the seal on it)

The BasicsUpdated on 7 October 2026we are coded

Every time you type a name into the browser, someone has to tell you exactly which computer to knock on. That simple service is the internet's directory - and it carries a seal that has to be checked before you trust the answer. Break the seal by accident, and the site doesn't fall to a hacker. The owner brings it down himself, while changing the key.

Checked on7 October 2026
In short: DNS (Domain Name System) is the system, dating from 1983, that serves as the internet's phone book - it turns the name you type (site.com) into the numeric address of the machine that has to answer. The resolver is the operator who makes that lookup for you, usually a service like 1.1.1.1 or your internet provider's own. DNSSEC is the seal on the answer: cryptographic proof that the address you get really comes from the domain's real owner, not from someone who slipped in along the way. Without the seal, the resolver trusts every answer; with it, the resolver checks the signature before it takes you anywhere.

The internet only speaks in numbers. Every machine on the network has an address - a long string of digits nobody memorizes. DNS (Domain Name System) is the directory that keeps the match between the name you remember and the number the computer understands. You type site.com, the directory answers with the address, the browser knocks exactly there. The service that makes that lookup for you is called a resolver - a server standing between you and the rest of the internet, answering every "where is this name" with the exact address.

But the directory doesn't carry a signature by default. The answer passes through several other servers before it reaches you. Any of them can technically change it along the way. Someone slipped in there - on someone else's Wi-Fi, at a compromised provider, somewhere in between - can return a different address instead of the real one. The same name is typed, the answer looks the same, but the address behind it points to a stranger's machine. The mail thief doesn't open your envelope. He swaps the sign on the door while you're not looking.

DNSSEC (Domain Name System Security Extensions) is exactly the seal missing from plain DNS. The domain's owner signs their record with a private key. Before handing you the address, the resolver checks the signature against the public counterpart of that same key. If it matches, the address is authentic, coming from the real owner, untouched along the way. If it doesn't match, the resolver refuses to answer instead of handing you a fake. The seal doesn't hide the content - DNS answers are public anyway - it proves the sender.

The seal has to be regularly replaced with a new key - routine maintenance, not an incident. That swap is called a rollover, and it has a strict order: the new key has to appear everywhere before the old one disappears from anywhere. Get the order wrong by even one day, and resolvers around the world detect a signature that no longer matches anything known, and by rule refuse to answer. The result isn't a slow site. The result is a site that, for half the world, simply doesn't exist - the directory goes silent, as if the name had never been registered.

The biggest rollover happens at the very top of the directory, in the root, where every check begins. On October 11, 2026 the root changes the key that signs its other keys (the key-signing key, KSK) for only the second time in history; the first time was in 2018. The new key, KSK-2024 (tag 38696), replaces KSK-2017 (tag 20326). It has been published in the root since January 11, 2025, so resolvers had time to learn it on their own under the RFC 5011 standard. If you run your own resolver that checks signatures, check that it already trusts the new key. ICANN explicitly advises not to assume the automation did the job. If your domain's DNS is on Cloudflare or you use 1.1.1.1, by Cloudflare's account you do nothing - their systems already trust it.

The seal doesn't hide the answer. It only proves who gave it.

Here's what holds it together

Here's what holds this whole construction together: trust that no user ever sees and almost no provider ever explains. For years, DNS ran without a seal, because the attack looked too specialized to be worth the effort. Then it turned out to be cheap. Today almost every registry adds DNSSEC by default. The problem just moved elsewhere - to the people who have to change the key on time, by hand or by automation, without a single day's mismatch.

So when you read that DNSSEC on an entire domain went down because of a rollover-timing mistake, don't treat it as a hacker attack. It's more the moment you notice how many things quietly depend on a single signature you never had to think about.

The visual is generated code art. No third-party images.
Official primary sources
→IETF RFC 1034: Domain Names - Concepts and Facilities (1987)→ICANN: DNSSEC - what is it and why is it important→ICANN: Root Zone KSK Rollover, 11 October 2026→IANA: DNSSEC Trust Anchors and Rollovers→Cloudflare: The keys to the Internet change on October 11, 2026