RFC 7129: Authenticated Denial of Existence in the DNS
In plain English — editorial summary, not part of the RFC
Authenticated denial of existence allows a resolver to validate that a certain domain name does not exist. It is also used to signal that a domain name exists but does not have the specific resource record (RR) type you were asking for. When returning a negative DNS Security Extensions (DNSSEC) response, a name server usually includes up to two NSEC records. With NSEC version 3 (NSEC3), this amount is three. This document provides additional background commentary and some context for the NSEC and NSEC3 mechanisms used by DNSSEC to provide authenticated denial-of-existence responses.
Document record
- Document ID
- RFC7129
- Published
- February 2014
- Authors
- R. Gieben; W. Mekking
- Status
- INFORMATIONAL
- Stream
- INDEPENDENT
- Area
- —
- Pages
- 30
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9276Guidance for NSEC3 Parameter SettingsCurrent
August 2022
- RFC 8198Aggressive Use of DNSSEC-Validated CacheUpdated
July 2017
- RFC 9077NSEC and NSEC3: TTLs and Aggressive UseCurrent
July 2021
- RFC 5155DNS Security (DNSSEC) Hashed Authenticated Denial of ExistenceUpdated
March 2008
- RFC 9824Compact Denial of Existence in DNSSECCurrent
September 2025
- RFC 3845DNS Security (DNSSEC) NextSECure (NSEC) RDATA FormatObsoleted
August 2004
- RFC 3755Legacy Resolver Compatibility for Delegation Signer (DS)Obsoleted
May 2004
- RFC 8483Yeti DNS TestbedCurrent
October 2018
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?