Home / Industry

NS1 and Salesforce Collaborate on Multi-Signer DNSSEC Implementation

NS1, the leader in next-generation DNS and application traffic management solutions, today announced it collaborated with experts from Salesforce on the first implementation of multi-signer DNSSEC, which enables the cryptographic signing of DNS records across zones with multiple DNS platforms. Engineers from both NS1 and Salesforce are leading the industry-wide initiative to provide a safer internet for all organizations and users through multi-signer DNSSEC, which is currently under review by the Internet Engineering Task Force (IETF).

DNSSEC, a set of enhancements to standard DNS functionality, prevents DNS spoofing and cache-poisoning attacks by cryptographically signing records in order to prove their authenticity. However, traditional implementations often break modern traffic management features like geo-routing and global server load balancing. These technical barriers have made it impossible to leverage DNS security extensions when using multiple DNS providers (platforms), which has limited enterprise adoption, leaving organizations unprotected.

“Multi-signer DNSSEC makes important strides in eliminating barriers to DNSSEC adoption by allowing for both redundancy and security without sacrificing the key proprietary features that ensure optimal performance,” explained NS1 Lead Software Engineer Jan V?elák. “The strategy allows each DNS provider to use separate zone signing keys for the records they serve, but all providers are required to agree on the total set of DNSSEC keys being used. This enables the successful validation of record authenticity between multiple DNS providers.”

V?elák and Salesforce Principal Software Engineer Shumon Huque served as co-authors, along with several other industry leaders, on the recent IETF draft that defines the innovative multi-signer DNSSEC strategy. Following this work, the NS1 and Salesforce teams collaborated to bring a real-world implementation to fruition, working with NS1 Managed DNS and the open-source DNS platform BIND.

“Our REST API enables NS1 DNS to retrieve public keys used for signing and also allows publishing the final DNSKEY record set and its signatures,” V?elák explained. “At the same time, we are building an open-source component that allows you to run NS1 and any common open-source DNS server (for example BIND) in the multi-signer DNSSEC configuration.”

Successful implementation of the new approach is well-timed, as cybercriminals are increasingly targeting DNS because of the critical role that it plays in the delivery of modern applications. The alarming increase in DNS-focused attacks recently compelled internet regulators and authorities, including ICANN and DHS, to issue directives calling for increased focus on security best practices like DNS redundancy and widespread adoption of DNSSEC.

“This advancement will have a significant impact on DNS security at a time when it is most critical. Enterprises are increasingly being targeted with DNS-focused attacks, but until now, basic security protocols required the sacrifice of certain traffic management features that were critical to performance and user experience,” said Huque. “This new approach makes it possible for organizations to deploy DNS security without compromising performance or advanced functionality, and the Salesforce team is proud to have collaborated with NS1 on a project that will not only benefit our users but also other enterprises around the world.”

NS1’s blog offers more details about the technical aspects of multi-signer DNSSEC implementation models and future areas for innovation. Read Jan V?elák’s post or visit https://ns1.com/dns-security to learn more.

By NS1, Intelligent DNS & Traffic Management

NS1 optimizes the delivery of the world’s most critical internet and enterprise applications. Only NS1’s platform is built on a modern API-first architecture that acts on real-time data and grows more powerful in complex environments, transforming DNS, DHCP, and IP Address Management (IPAM) into an intelligent, efficient, and automated system. NS1’s technology drives dramatic gains in IT efficiency and application performance, reliability, and security for the largest global enterprises, including Salesforce, LinkedIn, Dropbox, Nielsen, Pitney Bowes, Squarespace, Pandora and The Guardian.

Visit Page

Filed Under


Commenting is not available in this channel entry.
CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

I make a point of reading CircleID. There is no getting around the utility of knowing what thoughtful people are thinking and saying about our industry.

Co-designer of the TCP/IP Protocols & the Architecture of the Internet



Domain Names

Sponsored byVerisign

Threat Intelligence

Sponsored byWhoisXML API


Sponsored byDNIB.com


Sponsored byVerisign

New TLDs

Sponsored byRadix

IPv4 Markets

Sponsored byIPv4.Global

Brand Protection

Sponsored byCSC