NSEC / NSEC3 (DNSSEC-Existenzverneinung)
Embed This Widget
Add the script tag and a data attribute to embed this widget.
Embed via iframe for maximum compatibility.
<iframe src="https://tldfyi.com/iframe/glossary/nsec-nsec3/" width="420" height="400" frameborder="0" style="border:0;border-radius:10px;max-width:100%" loading="lazy"></iframe>
Paste this URL in WordPress, Medium, or any oEmbed-compatible platform.
https://tldfyi.com/glossary/nsec-nsec3/
Add a dynamic SVG badge to your README or docs.
[](https://tldfyi.com/glossary/nsec-nsec3/)
Use the native HTML custom element.
NSEC (Next Secure) und NSEC3 (RFC 5155) sind [[dnssec|DNSSEC]]-Eintragstypen, die beweisen, dass ein abgefragter Domainname nicht existiert — als «authentifizierte Existenzverneinung» bezeichnet. NSEC verknüpft Einträge alphabetisch und ermöglicht so die Zonenaufzählung (ein Datenschutzproblem). NSEC3 hasht die Eintragnamen vor der Verknüpfung und verhindert so eine einfache Aufzählung, während der kryptografische Nachweis der Nichtexistenz erhalten bleibt. NSEC3 wird für öffentliche Zonen mit sensiblen Daten dringend empfohlen.
Beispiel
When querying 'nonexistent.example.com' in a DNSSEC-signed zone, an NSEC3 record proves the name doesn't exist without revealing other names in the zone.