Official websites do not use .rip
A .gov website belongs to an official government organization in the United States.

We are building a provable archive!
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Secure Domain Name System (DNS) Deployment Guide | Comment on NIST SP 800-81r3
April 10, 2025

The Domain Name System (DNS) plays an integral role in every organization’s security posture by translating domain names into IP addresses. It can serve as an enforcement point for enterprise security policy and an indicator of potential malicious activity on a network. A disruption or attack against the DNS can impact an entire organization

NIST Special Publication (SP) 800-81r3 (Revision 3), Secure Domain Name System (DNS) Deployment Guide, describes the different roles of DNS and gives recommendations for protecting the integrity, availability, and confidentiality of DNS services, including:

    1. The role DNS plays in supporting a zero trust architecture, such as serving as both a policy enforcement point (PEP) and a source for information when evaluating access requests
    2. The role of hosting DNS information (authoritative DNS), including guidance on protecting the integrity and authenticity of DNS information using DNSSEC
    3. The role of recursive DNS, including guidance on protecting the confidentiality of client DNS queries

The public comment period is open through May 26, 2025. See the publication details for a copy of the draft. Additional information can be found on the NIST High Assurance Domains Project webpage.

NOTE: A call for patent claims is included on page ii of this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy – Inclusion of Patents in ITL Publications.

Related Topics

Security and Privacy: continuous monitoring, general security & privacy, threats

Technologies: internet

Applications: enterprise

Created April 08, 2025, Updated April 10, 2025