RFC 5452 · PROPOSED STANDARD · 2009

Measures for Making DNS More Resilient against Forged Answers

Overview

RFC 5452, “Measures for Making DNS More Resilient against Forged Answers”, is a Proposed Standard document published in January 2009 by A. Hubert, R. van Mook. It updates RFC 2181. The canonical text is published by the RFC Editor.

Abstract

The current Internet climate poses serious threats to the Domain Name System. In the interim period before the DNS protocol can be secured more fully, measures can already be taken to harden the DNS to make 'spoofing' a recursing nameserver many orders of magnitude harder.

Even a cryptographically secured DNS benefits from having the ability to discard bogus responses quickly, as this potentially saves large amounts of computation.

By describing certain behavior that has previously not been standardized, this document sets out how to make the DNS more resilient against accepting incorrect responses. This document updates RFC 2181. [STANDARDS-TRACK]

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 5452 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
This RFC updates
RFC 2181
Other RFCs from 2009

Who Is Online

In total there are 77 users online: 0 registered, 69 guests and 8 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Googlebot Other Bot PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372