RFC 7929 · EXPERIMENTAL · 2016

DNS-Based Authentication of Named Entities Bindings for OpenPGP

Overview

RFC 7929, “DNS-Based Authentication of Named Entities Bindings for OpenPGP”, is an Experimental document published in August 2016 by P. Wouters. The canonical text is published by the RFC Editor.

Abstract

OpenPGP is a message format for email (and file) encryption that lacks a standardized lookup mechanism to securely obtain OpenPGP public keys. DNS-Based Authentication of Named Entities (DANE) is a method for publishing public keys in DNS. This document specifies a DANE method for publishing and locating OpenPGP public keys in DNS for a specific email address using a new OPENPGPKEY DNS resource record. Security is provided via Secure DNS, however the OPENPGPKEY record is not a replacement for verification of authenticity via the "web of trust" or manual verification. The OPENPGPKEY record can be used to encrypt an email that would otherwise have to be sent unencrypted.

Abstract as published in the RFC, via rfc-editor.org.

What “Experimental” means

Describes a specification that is part of a research or development effort, published so the community can gain experience with it.

Read this RFC

The canonical text of RFC 7929 is hosted at rfc-editor.org. Available in TXT,HTML.

Other RFCs from 2016

Who Is Online

In total there are 250 users online: 0 registered, 241 guests and 9 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Googlebot Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372