Official websites do not use .rip
A .gov website belongs to an official government organization in the United States.

We are building a provable archive!
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 800-81 Rev. 3 (Initial Public Draft)

Secure Domain Name System (DNS) Deployment Guide

Date Published: April 10, 2025
Comments Due: May 26, 2025
Email Comments to: sp800-81@nist.gov

Author(s)

Scott Rose (NIST), Cricket Liu (Infoblox), Ross Gibson (Infoblox)

Announcement

The Domain Name System (DNS) plays an integral role in every organization’s security posture by translating domain names into IP addresses. It can serve as an enforcement point for enterprise security policy and an indicator of potential malicious activity on a network. A disruption or attack against the DNS can impact an entire organization

NIST Special Publication (SP) 800-81r3 (Revision 3), Secure Domain Name System (DNS) Deployment Guide, describes the different roles of DNS and gives recommendations for protecting the integrity, availability, and confidentiality of DNS services, including:

  1. The role DNS plays in supporting a zero trust architecture, such as serving as both a policy enforcement point (PEP) and a source for information when evaluating access requests
  2. The role of hosting DNS information (authoritative DNS), including guidance on protecting the integrity and authenticity of DNS information using DNSSEC
  3. The role of recursive DNS, including guidance on protecting the confidentiality of client DNS queries

The public comment period is open through May 26, 2025. Additional information can be found on the NIST High Assurance Domains Project webpage.

Abstract

Keywords

Authoritative Name Server; DNS Logging; DNS Security Extensions (DNSSEC); Domain Name System (DNS); Encrypted DNS; Protective DNS; Recursive Name Server; Resource Record (RR)
Control Families

None selected

Documentation

Publication:
https://doi.org/10.6028/NIST.SP.800-81r3.ipd
Download URL

Supplemental Material:
High Assurance Domains project

Document History:
04/10/25: SP 800-81 Rev. 3 (Draft)

Topics

Security and Privacy

continuous monitoring, general security & privacy, threats

Technologies

internet

Applications

enterprise