RFC 8198 · PROPOSED STANDARD · 2017

Aggressive Use of DNSSEC-Validated Cache

Overview

RFC 8198, “Aggressive Use of DNSSEC-Validated Cache”, is a Proposed Standard document published in July 2017 by K. Fujiwara, A. Kato, W. Kumari. It updates RFC 4035. It has since been updated by RFC 9077. The canonical text is published by the RFC Editor.

Abstract

The DNS relies upon caching to scale; however, the cache lookup generally requires an exact match. This document specifies the use of NSEC/NSEC3 resource records to allow DNSSEC-validating resolvers to generate negative answers within a range and positive answers from wildcards. This increases performance, decreases latency, decreases resource utilization on both authoritative and recursive servers, and increases privacy. Also, it may help increase resilience to certain DoS attacks in some circumstances.

This document updates RFC 4035 by allowing validating resolvers to generate negative answers based upon NSEC/NSEC3 records and positive answers in the presence of wildcards.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 8198 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
This RFC updates
RFC 4035
Updated by
RFC 9077
Other RFCs from 2017

Who Is Online

In total there are 79 users online: 0 registered, 72 guests and 7 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Other Bot PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372