Skip to main content

Recommendations for DNSSEC Resolvers Operators

Document Type Replaced Internet-Draft (dnsop WG)
Expired & archived
Authors Daniel Migault , Edward Lewis , Dan York
Last updated 2020-05-18 (Latest revision 2020-04-29)
Replaced by draft-ietf-dnsop-dnssec-validator-requirements
RFC stream Internet Engineering Task Force (IETF)
Intended RFC status (None)
Additional resources Mailing list discussion
Stream WG state Adopted by a WG
Document shepherd (None)
IESG IESG state Replaced by draft-ietf-dnsop-dnssec-validator-requirements
Consensus boilerplate Unknown
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:


The DNS Security Extensions define a process for validating received data and assert them authentic and complete as opposed to forged. This document is focused clarifying the scope and responsibilities of DNSSEC Resolver Operators (DRO) as well as operational recommendations that DNSSEC validators operators SHOULD put in place in order to implement sufficient Trust that makes DNSSEC validation output accurate. The recommendations described in this document include, provisioning mechanisms as well as monitoring and management mechanisms.


Daniel Migault
Edward Lewis
Dan York

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)