RFC 8945 · INTERNET STANDARD · 2020

Secret Key Transaction Authentication for DNS

Overview

RFC 8945, “Secret Key Transaction Authentication for DNS”, is an Internet Standard document published in November 2020 by F. Dupont, S. Morris, P. Vixie, D. Eastlake 3rd, O. Gudmundsson, B. Wellington. It obsoletes RFC 2845, RFC 4635. The canonical text is published by the RFC Editor.

Abstract

This document describes a protocol for transaction-level authentication using shared secrets and one-way hashing. It can be used to authenticate dynamic updates to a DNS zone as coming from an approved client or to authenticate responses as coming from an approved name server.

No recommendation is made here for distributing the shared secrets; it is expected that a network administrator will statically configure name servers and clients using some out-of-band mechanism.

This document obsoletes RFCs 2845 and 4635.

Abstract as published in the RFC, via rfc-editor.org.

What “Internet Standard” means

A mature, widely-implemented specification that has completed the full IETF standards process — the highest maturity level on the standards track.

Read this RFC

The canonical text of RFC 8945 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Relationships to other RFCs
This RFC obsoletes
RFC 2845 RFC 4635
Other RFCs from 2020

Who Is Online

In total there are 59 users online: 0 registered, 52 guests and 7 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Other Bot PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372