RFC 9018 · PROPOSED STANDARD · 2021

Interoperable Domain Name System Server Cookies

Overview

RFC 9018, “Interoperable Domain Name System Server Cookies”, is a Proposed Standard document published in April 2021 by O. Sury, W. Toorop, D. Eastlake 3rd, M. Andrews. It updates RFC 7873. The canonical text is published by the RFC Editor.

Abstract

DNS Cookies, as specified in RFC 7873, are a lightweight DNS transaction security mechanism that provide limited protection to DNS servers and clients against a variety of denial-of-service amplification, forgery, or cache-poisoning attacks by off-path attackers.

This document updates RFC 7873 with precise directions for creating Server Cookies so that an anycast server set including diverse implementations will interoperate with standard clients, with suggestions for constructing Client Cookies in a privacy-preserving fashion, and with suggestions on how to update a Server Secret. An IANA registry listing the methods and associated pseudorandom function suitable for creating DNS Server Cookies has been created with the method described in this document as the first and, as of the time of publication, only entry.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 9018 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Relationships to other RFCs
This RFC updates
RFC 7873
Other RFCs from 2021

Who Is Online

In total there are 24 users online: 0 registered, 18 guests and 6 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Bingbot Facebook Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 354