RFC 4956 · EXPERIMENTAL · 2007

DNS Security Opt-In

Overview

RFC 4956, “DNS Security Opt-In”, is an Experimental document published in July 2007 by R. Arends, M. Kosters, D. Blacka. The canonical text is published by the RFC Editor.

Abstract

In the DNS security (DNSSEC) extensions, delegations to unsigned subzones are cryptographically secured. Maintaining this cryptography is not always practical or necessary. This document describes an experimental "Opt-In" model that allows administrators to omit this cryptography and manage the cost of adopting DNSSEC with large zones. This memo defines an Experimental Protocol for the Internet community.

Abstract as published in the RFC, via rfc-editor.org.

What “Experimental” means

Describes a specification that is part of a research or development effort, published so the community can gain experience with it.

Read this RFC

The canonical text of RFC 4956 is hosted at rfc-editor.org. Available in TXT,HTML.

Other RFCs from 2007

Who Is Online

In total there are 164 users online: 0 registered, 159 guests and 5 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: Applebot Facebook Other Bot Other Crawler SemrushBot

Users active in the past 15 minutes. Total registered members: 354