🧮 NSEC3 & CDS

Authenticated denial (NSEC vs NSEC3), RFC 9276 iteration compliance and automated key rollover (CDS/CDNSKEY) · all insights

Signed zones prove that a name does not exist with NSEC or NSEC3 records. RFC 9276 recommends NSEC3 with zero extra iterations and no salt; this page measures how many .dk zones follow that, which providers don't, and who publishes CDS/CDNSKEY for automated key rollovers. Data comes from our own scanners, which re-resolve every .dk domain in the zone roughly once a week.

Based on 55,778 domains probed so far (4.1% of the zone). Our scanners refresh these probes at least every 30 days, so the numbers fill in and settle over the first month.

🧮 NSEC3 iterations

Of 37,234 signed zones probed, 21,138 (56.8%) use NSEC3, 15,239 (40.9%) use a classic NSEC chain, which lets anyone list every name in the zone, and 857 (2.3%) use compact denial (RFC 9824, Cloudflare's "black lies"), which can't be walked. RFC 9276 asks NSEC3 zones for 0 extra iterations and no salt: iterations cost resolvers CPU for no security gain. 10,189 NSEC3 zones (48.2%) still use iterations and 10,210 use a salt; 92 use opt-out.

IterationsZonesShare
010,949
51.8%
19,259
43.8%
51
0.0%
7504
2.4%
81
0.0%
10366
1.7%
202
0.0%
212
0.0%
5054
0.3%

List the zones with iterations > 0 →

🏢 NSEC3 by DNS provider

ProviderNSEC3 zonesIterations > 0Salted
one.com9,7700.1%0.1%
dandomain.dk4,859100.0%100.0%
curanet.dk2,286100.0%100.0%
scannet2.dk1,019100.0%100.0%
hyp.net5870%0.0%
wannafind.dk378100.0%100.0%
sitnet.dk292100.0%100.0%
dnsserver.dk286100.0%100.0%
nordicway.dk23564.7%64.7%
e-studio.dk18498.9%98.9%
loopia.se1500%0.0%
123hotel.dk78100.0%100.0%
netgiganten.dk6496.9%96.9%
aveo.dk64100.0%100.0%
simpleagencygroup.dk51100.0%100.0%
gnrx.dk41100.0%100.0%
dnsadmin.dk3987.2%100.0%
azehosting.net3794.6%94.6%
wixdns.net35100.0%100.0%
hostonline.dk35100.0%100.0%
desec.io340%0.0%
yayhosting.dk33100.0%100.0%
eurodns.com280%0.0%
deic.dk270%0.0%
web-solutions.dk260%0.0%

🔄 CDS / CDNSKEY (automated DS updates)

CDS and CDNSKEY records let a DNS operator hand key rollovers to the registry automatically (RFC 7344/8078). 13,834 of 39,260 signed zones (35.2%) publish them; 32 publish the delete signal, asking the registry to remove their DS and turn DNSSEC off.

dhd.dk [/] search Domains, Hosts & DNS — .dk zone