Compact Denial of Existence in DNSSEC
RFC 9824, “Compact Denial of Existence in DNSSEC”, is a Proposed Standard document published in September 2025 by S. Huque, C. Elmerot, O. Gudmundsson. It updates RFC 4034, RFC 4035. The canonical text is published by the RFC Editor.
Abstract
This document describes a technique to generate a signed DNS response on demand for a nonexistent name by claiming that the name exists but doesn't have any data for the queried record type. Such responses require only one minimally covering NSEC or NSEC3 record, allow online signing servers to minimize signing operations and response sizes, and prevent zone content disclosure.
This document updates RFCs 4034 and 4035.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9824 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9825 Extensions to OSPF for Advertising Prefix Administrative Tags
- RFC 9826 A YANG Data Model for the Path Computation Element Communication Protocol
- RFC 9827 Renaming the Extended Sequence Numbers Transform Type in the Internet Key Exchange Protocol Version 2
- RFC 9820 Authentication Service Based on the Extensible Authentication Protocol for Use with the Constrained Application Protocol
- RFC 9828 RTP Payload Format for JPEG 2000 Streaming with Sub-Codestream Latency
- RFC 9819 Argument Signaling for BGP Services in Segment Routing over IPv6
- RFC 9829 Handling of Resource Public Key Infrastructure Certificate Revocation List Number Extensions
- RFC 9818 DHCPv6 Prefix Delegation on IPv6 Customer Edge Routers in LANs