RFC 3445 · PROPOSED STANDARD · 2002

Limiting the Scope of the KEY Resource Record

Overview

RFC 3445, “Limiting the Scope of the KEY Resource Record”, is a Proposed Standard document published in December 2002 by D. Massey, S. Rose. It updates RFC 2535. It has been obsoleted by RFC 4033, RFC 4034, RFC 4035 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.

Abstract

This document limits the Domain Name System (DNS) KEY Resource Record (RR) to only keys used by the Domain Name System Security Extensions (DNSSEC). The original KEY RR used sub-typing to store both DNSSEC keys and arbitrary application keys. Storing both DNSSEC and application keys with the same record type is a mistake. This document removes application keys from the KEY record by redefining the Protocol Octet field in the KEY RR Data. As a result of removing application keys, all but one of the flags in the KEY record become unnecessary and are redefined. Three existing application key sub-types are changed to reserved, but the format of the KEY record is not changed. This document updates RFC 2535. [STANDARDS-TRACK]

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 3445 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
Obsoleted by
RFC 4033 RFC 4034 RFC 4035
This RFC updates
RFC 2535
Other RFCs from 2002

Who Is Online

In total there are 44 users online: 0 registered, 37 guests and 7 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Other Bot PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372