DNS Infrastructure & Naming Conventions
Help us test our DNSSEC implementation

Help us test our DNSSEC implementation

1/29/2015 · Filippo Valsorda

What this post added

This post marks the initial public release of Cloudflare's DNSSEC implementation by publishing a signed zone for www.cloudflare.com. It details the use of 'signing on the fly' to prevent NSEC record exposure of subdomains, the adoption of ECDSA for smaller DNS answers to mitigate reflection attacks, and the provision of a managed solution to abstract DNSSEC complexity from users. It also includes a DiG output example and a visualization of domain signatures.

Read the original post ↗