RFC 8976: Message Digest for DNS Zones
In plain English — editorial summary, not part of the RFC
This document describes a protocol and new DNS Resource Record that provides a cryptographic message digest over DNS zone data at rest. The ZONEMD Resource Record conveys the digest data in the zone itself. When used in combination with DNSSEC, ZONEMD allows recipients to verify the zone contents for data integrity and origin authenticity. This provides assurance that received zone data matches published data, regardless of how the zone data has been transmitted and received. When used without DNSSEC, ZONEMD functions as a checksum, guarding only against unintentional changes. ZONEMD does not replace DNSSEC: DNSSEC protects individual RRsets (DNS data with fine granularity), whereas ZONEMD protects a zone's data as a whole, whether consumed by authoritative name servers, recursive name servers, or any other applications. As specified herein, ZONEMD is impractical for large, dynamic zones due to the time and resources required for digest calculation. However, the ZONEMD record is extensible so that new digest schemes may be added in the future to support large, dynamic zones.
Document record
- Document ID
- RFC8976
- Published
- February 2021
- Authors
- D. Wessels; P. Barber; M. Weinberg; W. Kumari; W. Hardaker
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- ops
- Pages
- 31
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8749Moving DNSSEC Lookaside Validation (DLV) to Historic StatusCurrent
March 2020
- RFC 9276Guidance for NSEC3 Parameter SettingsCurrent
August 2022
- RFC 9364DNS Security Extensions (DNSSEC)Current
February 2023
- RFC 8509A Root Key Trust Anchor Sentinel for DNSSECCurrent
December 2018
- RFC 9726Operational Considerations for Use of DNS in Internet of Things (IoT) DevicesCurrent
March 2025
- RFC 8145Signaling Trust Anchor Knowledge in DNS Security Extensions (DNSSEC)Updated
April 2017
- RFC 9824Compact Denial of Existence in DNSSECCurrent
September 2025
- RFC 9904DNSSEC Cryptographic Algorithm Recommendation Update ProcessCurrent
November 2025
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?