NSEC / NSEC3 (Penolakan Keberadaan DNSSEC)
Embed This Widget
Add the script tag and a data attribute to embed this widget.
Embed via iframe for maximum compatibility.
<iframe src="https://tldfyi.com/iframe/glossary/nsec-nsec3/" width="420" height="400" frameborder="0" style="border:0;border-radius:10px;max-width:100%" loading="lazy"></iframe>
Paste this URL in WordPress, Medium, or any oEmbed-compatible platform.
https://tldfyi.com/glossary/nsec-nsec3/
Add a dynamic SVG badge to your README or docs.
[](https://tldfyi.com/glossary/nsec-nsec3/)
Use the native HTML custom element.
NSEC (Next Secure) dan NSEC3 (RFC 5155) adalah jenis rekaman [[dnssec|DNSSEC]] yang digunakan untuk membuktikan bahwa nama domain yang dikueri tidak ada — disebut 'penolakan keberadaan yang terautentikasi'. NSEC menghubungkan rekaman secara alfabetis, memungkinkan enumerasi zona (masalah privasi). NSEC3 melakukan hash pada nama rekaman sebelum menghubungkannya, mencegah enumerasi mudah sekaligus memberikan bukti kriptografis tentang ketidakberadaan. NSEC3 sangat direkomendasikan untuk zona publik yang menangani data sensitif.
Contoh
When querying 'nonexistent.example.com' in a DNSSEC-signed zone, an NSEC3 record proves the name doesn't exist without revealing other names in the zone.