DNS Security Extensions (DNSSEC)
Extensions that let a resolver verify DNS answers through digital signatures and a chain of trust from the root, giving origin authentication and integrity but no confidentiality.
DNS Security Extensions, defined in RFCs 4033, 4034 and 4035 (2005), add digital signatures to the Domain Name System. A zone signs its record sets, publishes its public keys in the zone, and has a fingerprint of its key published in the parent zone. A validating resolver can then follow that chain upward to the root, whose key it already trusts, and confirm that an answer came from the zone’s owner and was not altered on the way. It can also prove that a name does not exist.
The defence it provides is against forged answers, above all DNS cache poisoning: a poisoned record for a signed zone will fail validation at a validating resolver, because the attacker cannot produce a valid signature. What DNSSEC does not do is encrypt. Queries and answers remain readable by anyone on the path, which is the gap DNS over HTTPS addresses. Nor does it help if an attacker controls the domain’s registration or signing keys, as in some DNS hijacking.
Exam relevance: questions in this area tend to test the property, not the record types. DNSSEC provides integrity and origin authentication for DNS data, and an option claiming it provides confidentiality is a common trap. A scenario about preventing spoofed or poisoned DNS responses is likely to point to DNSSEC.