
DNSSEC (Domain Name System Security Extensions) targets a specific DNS vulnerability that exposes Internet users to cache poisoning, or “man in the middle” attacks. Its implementation addresses this vulnerability by adding a digital signature to DNS query responses, allowing verification of those responses through an unbroken communication chain.
Registrants who collect personal information and, in particular, those who gather payment information are good candidates for DNSSEC. These registrants will be able to submit additional record information, called Delegation Signer (DS) information, to their DNS providers in order to enable DNSSEC for their domain names.
In 2009, the Department of Commerce approved the implementation of DNSSEC for .US. Since that time, Neustar has created a testing environment and has worked with early adopters in order to develop a reliable implementation of DNSSEC for the .US zone. This service will be available to .US domain name holders next month when, on June 7, the .US zone will begin accepting DS records.


