RFC 1034
Read at RFC Editor References
Standards and implementation references behind the guide
The DNS is specified across many documents. This list favours current RFC Editor pages and includes foundational specifications where they remain essential.
Editorial approach
The prose in this guide is original and vendor-neutral. Examples use names and addresses reserved for documentation. Standards links open the canonical RFC Editor version.
RFC 1035
Read at RFC Editor Domain Names — Implementation and Specification
RFC 2308
Read at RFC Editor Negative Caching of DNS Queries
RFC 4033
Read at RFC Editor DNS Security Introduction and Requirements
RFC 4034
Read at RFC Editor Resource Records for DNSSEC
RFC 4035
Read at RFC Editor Protocol Modifications for DNSSEC
RFC 5155
Read at RFC Editor NSEC3 Hashed Authenticated Denial of Existence
RFC 5737
Read at RFC Editor IPv4 Address Blocks Reserved for Documentation
RFC 3849
Read at RFC Editor IPv6 Address Prefix Reserved for Documentation
RFC 5936
Read at RFC Editor DNS Zone Transfer Protocol (AXFR)
RFC 1995
Read at RFC Editor Incremental Zone Transfer in DNS (IXFR)
RFC 6698
Read at RFC Editor DANE TLSA
RFC 7671
Read at RFC Editor DANE Operational Guidance
RFC 7672
Read at RFC Editor DANE for SMTP
RFC 7858
Read at RFC Editor DNS over TLS
RFC 8198
Read at RFC Editor Aggressive Use of DNSSEC-Validated Cache
RFC 8484
Read at RFC Editor DNS over HTTPS
RFC 8945
Read at RFC Editor Secret Key Transaction Authentication for DNS (TSIG)
RFC 9018
Read at RFC Editor Interoperable DNS Server Cookies
RFC 9077
Read at RFC Editor NSEC and NSEC3 TTLs and Aggressive Use
RFC 9103
Read at RFC Editor DNS Zone Transfer over TLS
RFC 9156
Read at RFC Editor QNAME Minimisation to Improve Privacy
RFC 9250
Read at RFC Editor DNS over Dedicated QUIC Connections
RFC 9364
Read at RFC Editor DNS Security Extensions (DNSSEC)
RFC 9460
Read at RFC Editor Service Binding and Parameter Specification
RFC 9499
Read at RFC Editor DNS Terminology
RFC 9520
Read at RFC Editor Negative Caching of DNS Resolution Failures
RFC 2606
Read at RFC Editor Reserved Top Level DNS Names
Implementation documentation
Authoritative service and host confinement
These upstream manuals document the implementation-specific configuration shown in the NSD hardening guide.
NSD
Read upstream documentation NLnet Labs NSD configuration guide
nsd.conf(5)
Read upstream manual NSD configuration-file reference
AppArmor
Read upstream documentation Profile types, syntax and resource rules
systemd.exec(5)
Read upstream manual Service execution and sandbox directives
systemd-analyze(1)
Read upstream manual