NSEC / NSEC3 (DNSSEC Denial of Existence)
Embed This Widget
Add the script tag and a data attribute to embed this widget.
Embed via iframe for maximum compatibility.
<iframe src="https://tldfyi.com/iframe/glossary/nsec-nsec3/" width="420" height="400" frameborder="0" style="border:0;border-radius:10px;max-width:100%" loading="lazy"></iframe>
Paste this URL in WordPress, Medium, or any oEmbed-compatible platform.
https://tldfyi.com/glossary/nsec-nsec3/
Add a dynamic SVG badge to your README or docs.
[](https://tldfyi.com/glossary/nsec-nsec3/)
Use the native HTML custom element.
NSEC (Next Secure) and NSEC3 (RFC 5155) are [[dnssec|DNSSEC]] record types used to prove that a queried domain name does not exist — 'authenticated denial of existence.' NSEC links records alphabetically, enabling zone enumeration (a privacy concern). NSEC3 hashes the record names before linking, preventing easy enumeration while still providing cryptographic proof of non-existence. NSEC3 is strongly preferred for public zones handling sensitive data.
Example
When querying 'nonexistent.example.com' in a DNSSEC-signed zone, an NSEC3 record proves the name doesn't exist without revealing other names in the zone.