RFC 9103 · PROPOSED STANDARD · 2021

DNS Zone Transfer over TLS

Overview

RFC 9103, “DNS Zone Transfer over TLS”, is a Proposed Standard document published in August 2021 by W. Toorop, S. Dickinson, S. Sahib, P. Aras, A. Mankin. It updates RFC 1995, RFC 5936, RFC 7766. The canonical text is published by the RFC Editor.

Abstract

DNS zone transfers are transmitted in cleartext, which gives attackers the opportunity to collect the content of a zone by eavesdropping on network connections. The DNS Transaction Signature (TSIG) mechanism is specified to restrict direct zone transfer to authorized clients only, but it does not add confidentiality. This document specifies the use of TLS, rather than cleartext, to prevent zone content collection via passive monitoring of zone transfers: XFR over TLS (XoT). Additionally, this specification updates RFC 1995 and RFC 5936 with respect to efficient use of TCP connections and RFC 7766 with respect to the recommended number of connections between a client and server for each transport.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 9103 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Relationships to other RFCs
This RFC updates
RFC 1995 RFC 5936 RFC 7766
Other RFCs from 2021

Who Is Online

In total there are 76 users online: 0 registered, 69 guests and 7 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: Applebot Baiduspider Bingbot Googlebot Other Bot PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372