DNS Security

Sponsored
by

Noteworthy

Domain Research and Monitoring: Keeping an Eye on the Web for You

WHOIS History API: Powering Domain Investigations

Reverse WHOIS: A Powerful Process in Cybersecurity

DNS Security / Recently Commented

The DNSSEC “Onus of Reality Check” Shifted to gTLD Administrations by ICANN

Last month, there was an exchange of letters between a gTLD administration and ICANN about DNSSEC deployment. This gTLD administration is PIR or Public Interest Registry, the gTLD administration for the .org TLD. Interestingly, PIR is a non-profit organization that makes significant contributions to ISOC (Internet Society) initiatives: thus, both ICANN and PIR are organizations dedicated to the well-being of the Internet. more

DNSSEC Deployment at the Root

The DNSSEC is a security protocol for providing cryptographic assurance (i.e. using the public key cryptography digital signature technology) to the data retrieved from the DNS distributed database (RFC4033). DNSSEC deployment at the root is said to be subject to politics, but there is seldom detailed discussion about this "DNS root signing" politics. Actually, DNSSEC deployment requires more than signing the DNS root zone data; it also involves secure delegations from the root to the TLDs, and DNSSEC deployment by TLD administrations (I omit other participants involvement as my focus is policy around the DNS root). There is a dose of naivety in the idea of detailing the political aspects of the DNS root, but I volunteer! My perspective is an interested observer. more

The Reporting Gap: What Happens Between a DNS Abuse Complaint and a Takedown

DNS abuse enforcement can stop abusive domains and drive systemic registrar reforms, but reporting barriers, inconsistent response times, and poorly documented complaints leave many phishing sites active before actionable cases ever reach enforcement. more

G7 Cyber Agencies Urge Immediate Post-Quantum Migration Planning

G7 cybersecurity agencies are pressing governments and organizations to inventory cryptographic dependencies and accelerate post-quantum migration as long transition timelines and future quantum attacks threaten Internet security infrastructure. more

From Forgotten to Exploited: How AI Changes the Dangling DNS Threat

Dangling DNS records can expose trusted corporate subdomains to takeover, while AI-assisted reconnaissance makes abandoned resources easier to find, increasing the need for continuous DNS monitoring rather than periodic audits. more

ICANN Terminates Two Registrars as DNS Abuse and Compliance Failures Escalate

ICANN has terminated two registrar accreditation agreements after unresolved compliance failures, citing Trustname's handling of DNS abuse and IPIP's failures involving RDAP, registration data escrow, accreditation fees, and access to non-public registration data. more

ICANN’s New Data Sharpens the Picture of DNS-abuse Enforcement

ICANN's updated DNS-abuse data distinguishes allegations from actionable complaints and malicious registrations from compromised domains, offering a clearer test of whether tougher contractual requirements are strengthening enforcement or simply generating a larger volume of reports. more

Beyond Protocol and Policy: Why Project Jake is Reshaping the Architecture of Internet Trust

Project Jake aims to bridge the divide between internet protocols and policy, offering registries, law enforcement and rights holders a decentralised framework for accessing domain-registration data securely while navigating privacy laws and institutional gridlock. more

Open-Weight AI: Open to Whom?

The push for open-weight AI promises broader access and competition, but true openness requires more than releasing model weights. Compute, infrastructure, training data, security, and control ultimately determine who can meaningfully benefit from open AI. more

DNS Security Gets Fixed When Someone Notices - Not Before

A study of 309 universities, museums and sports brands finds DNS security follows visible threats rather than technical risk, leaving organisations well protected against familiar attacks while quieter weaknesses in critical infrastructure persist unnoticed. more

Phantom Squatting: When LLMs’ Hallucination Becomes an Attacker’s Best Friend

As AI reshapes cybersecurity, attackers are exploiting a fundamental weakness in large language models. Phantom squatting turns hallucinated domain names into trusted attack vectors, creating a new class of DNS abuse that defenders cannot solve by eliminating hallucinations alone. more

The 2024-2026 Root Zone KSK Rollover: Updates and Observations

Roughly a year and a half ago, Verisign and ICANN began the important, multi-year process of updating the cryptographic key that secures the authoritative DNS root zone. This work has been largely invisible to the public, but vital to the security of many everyday online activities. more

The Question Isn’t Whether the Harm Is Real - It’s Who Should Act

Measuring online abuse can reveal its scale, but not who should intervene. Effective policy must distinguish harm from contractual responsibility, identify the actors best placed to act, and target remedies where they can work effectively. more

.PK ccTLD Governance Issues and Pakistan’s Digital Future

Pakistan's .pk domain has long been controlled by a private company abroad, raising concerns over digital sovereignty, cybersecurity and accountability. Repeated breaches, offshore infrastructure and weak governance have left a critical national asset exposed and contested. more

When AI Writes the Scam: How Artificial Intelligence Is Making DNS Abuse Harder to Detect

Artificial intelligence is transforming phishing and DNS abuse, erasing the linguistic clues that once exposed scams. As attacks become personalised, automated and multilingual, governance frameworks are struggling to keep pace with a rapidly expanding threat surface. more