RFC 9077: NSEC and NSEC3: TTLs and Aggressive Use
In plain English — editorial summary, not part of the RFC
Due to a combination of unfortunate wording in earlier documents, aggressive use of NSEC and NSEC3 records may deny the existence of names far beyond the intended lifetime of a denial. This document changes the definition of the NSEC and NSEC3 TTL to correct that situation. This document updates RFCs 4034, 4035, 5155, and 8198.
Document record
- Document ID
- RFC9077
- Published
- July 2021
- Authors
- P. van Dijk
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- ops
- Pages
- 8
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9276Guidance for NSEC3 Parameter SettingsCurrent
August 2022
- RFC 9824Compact Denial of Existence in DNSSECCurrent
September 2025
- RFC 8976Message Digest for DNS ZonesCurrent
February 2021
- RFC 8901Multi-Signer DNSSEC ModelsCurrent
September 2020
- RFC 9364DNS Security Extensions (DNSSEC)Current
February 2023
- RFC 8749Moving DNSSEC Lookaside Validation (DLV) to Historic StatusCurrent
March 2020
- RFC 8683Additional Deployment Guidelines for NAT64/464XLAT in Operator and Enterprise NetworksCurrent
November 2019
- RFC 9615Automatic DNSSEC Bootstrapping Using Authenticated Signals from the Zone's OperatorCurrent
July 2024
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?