Enregistrement DNSKEY
Embed This Widget
Add the script tag and a data attribute to embed this widget.
Embed via iframe for maximum compatibility.
<iframe src="https://tldfyi.com/iframe/glossary/dnskey-record/" width="420" height="400" frameborder="0" style="border:0;border-radius:10px;max-width:100%" loading="lazy"></iframe>
Paste this URL in WordPress, Medium, or any oEmbed-compatible platform.
https://tldfyi.com/glossary/dnskey-record/
Add a dynamic SVG badge to your README or docs.
[](https://tldfyi.com/glossary/dnskey-record/)
Use the native HTML custom element.
Un enregistrement DNSKEY (RFC 4034) stocke la clé cryptographique publique utilisée pour vérifier les signatures [[dnssec|DNSSEC]] dans une zone. Chaque zone signée DNSSEC publie au moins une Zone Signing Key (ZSK) et une Key Signing Key (KSK). Le hachage du KSK est publié en tant qu'enregistrement DS dans la zone parente, formant la [[dnssec|chaîne de confiance]] depuis la racine DNS. Les enregistrements DNSKEY ont un format de champs spécifique pour les indicateurs, le protocole et l'algorithme.
Exemple
Running `dig DNSKEY cloudflare.com` returns the public keys Cloudflare uses to sign its DNSSEC records — validators use these keys to verify all other DNSSEC signatures in the zone.