NSEC / NSEC3 (การปฏิเสธการมีอยู่ใน DNSSEC)
Embed This Widget
Add the script tag and a data attribute to embed this widget.
Embed via iframe for maximum compatibility.
<iframe src="https://tldfyi.com/iframe/glossary/nsec-nsec3/" width="420" height="400" frameborder="0" style="border:0;border-radius:10px;max-width:100%" loading="lazy"></iframe>
Paste this URL in WordPress, Medium, or any oEmbed-compatible platform.
https://tldfyi.com/glossary/nsec-nsec3/
Add a dynamic SVG badge to your README or docs.
[](https://tldfyi.com/glossary/nsec-nsec3/)
Use the native HTML custom element.
NSEC (Next Secure) และ NSEC3 (RFC 5155) คือประเภทเรคคอร์ด [[dnssec|DNSSEC]] ที่ใช้พิสูจน์ว่าชื่อโดเมนที่ค้นหาไม่มีอยู่จริง เรียกว่า 'การปฏิเสธการมีอยู่ที่ผ่านการรับรอง' NSEC เชื่อมโยงเรคคอร์ดตามลำดับตัวอักษรซึ่งทำให้สามารถระบุรายการโซนได้ (ซึ่งเป็นข้อกังวลด้านความเป็นส่วนตัว) NSEC3 แฮชชื่อเรคคอร์ดก่อนเชื่อมโยงเพื่อป้องกันการระบุรายการได้ง่ายในขณะที่ยังคงให้หลักฐานการเข้ารหัสของการไม่มีอยู่ NSEC3 เป็นที่แนะนำอย่างยิ่งสำหรับโซนสาธารณะที่จัดการข้อมูลที่ละเอียดอ่อน.
ตัวอย่าง
When querying 'nonexistent.example.com' in a DNSSEC-signed zone, an NSEC3 record proves the name doesn't exist without revealing other names in the zone.