RFC 4034: Resource Records for the DNS Security Extensions
In plain English — editorial summary, not part of the RFC
This document is part of a family of documents that describe the DNS Security Extensions (DNSSEC). The DNS Security Extensions are a collection of resource records and protocol modifications that provide source authentication for the DNS. This document defines the public key (DNSKEY), delegation signer (DS), resource record digital signature (RRSIG), and authenticated denial of existence (NSEC) resource records. The purpose and format of each resource record is described in detail, and an example of each resource record is given. This document obsoletes RFC 2535 and incorporates changes from all updates to RFC 2535. [STANDARDS-TRACK]
Document record
- Document ID
- RFC4034
- Published
- March 2005
- Authors
- R. Arends; R. Austein; M. Larson; D. Massey; S. Rose
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- int
- Pages
- 29
- Also known as
- —
Topics
Standards lineage
This document is one revision in a chain of 13 RFCs, each formally replacing the one before it.
- RFC 2065 (1997)
- RFC 2535 (1999)
- RFC 3008 (2000)
- RFC 3090 (2001)
- RFC 3445 (2002)
- RFC 3655 (2003)
- RFC 3658 (2003)
- RFC 3755 (2004)
- RFC 3757 (2004)
- RFC 3845 (2004)
- RFC 4033 (2005)
- RFC 4034 (2005)
- RFC 4035 (2005) ✓
Read the full history of Protocol Modifications for the DNS Security Extensions →
Referenced by
7 later RFCs formally update or obsolete part of this document.
- RFC 4470Minimally Covering NSEC Records and DNSSEC On-line SigningCurrent
April 2006
- RFC 6014Cryptographic Algorithm Identifier Allocation for DNSSECUpdated
November 2010
- RFC 6840Clarifications and Implementation Notes for DNS Security (DNSSEC)Updated
February 2013
- RFC 6944Applicability Statement: DNS Security (DNSSEC) DNSKEY Algorithm Implementation StatusObsoleted
April 2013
- RFC 9077NSEC and NSEC3: TTLs and Aggressive UseCurrent
July 2021
- RFC 9824Compact Denial of Existence in DNSSECCurrent
September 2025
- RFC 9905Deprecating the Use of SHA-1 in DNSSEC Signature AlgorithmsCurrent
November 2025
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 4033DNS Security Introduction and RequirementsUpdated
March 2005
- RFC 4035Protocol Modifications for the DNS Security ExtensionsUpdated
March 2005
- RFC 3007Secure Domain Name System (DNS) Dynamic UpdateCurrent
November 2000
- RFC 4255Using DNS to Securely Publish Secure Shell (SSH) Key FingerprintsCurrent
January 2006
- RFC 4310Domain Name System (DNS) Security Extensions Mapping for the Extensible Provisioning Protocol (EPP)Obsoleted
December 2005
- RFC 2540Detached Domain Name System (DNS) InformationCurrent
March 1999
- RFC 2539Storage of Diffie-Hellman Keys in the Domain Name System (DNS)Updated
March 1999
- RFC 4016Protocol for Carrying Authentication and Network Access (PANA) Threat Analysis and Security RequirementsCurrent
March 2005
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?