Bản ghi DNSKEY
Embed This Widget
Add the script tag and a data attribute to embed this widget.
Embed via iframe for maximum compatibility.
<iframe src="https://tldfyi.com/iframe/glossary/dnskey-record/" width="420" height="400" frameborder="0" style="border:0;border-radius:10px;max-width:100%" loading="lazy"></iframe>
Paste this URL in WordPress, Medium, or any oEmbed-compatible platform.
https://tldfyi.com/glossary/dnskey-record/
Add a dynamic SVG badge to your README or docs.
[](https://tldfyi.com/glossary/dnskey-record/)
Use the native HTML custom element.
Bản ghi DNSKEY (RFC 4034) lưu trữ khóa mật mã công khai dùng để xác minh chữ ký [[dnssec|DNSSEC]] trong một vùng. Mỗi vùng được ký bằng DNSSEC công bố ít nhất một ZSK (Zone Signing Key) và một KSK (Key Signing Key). Hash của KSK được công bố dưới dạng bản ghi DS trong vùng cha, tạo thành [[dnssec|chuỗi tin cậy]] từ gốc DNS xuống dưới. Bản ghi DNSKEY có định dạng trường cờ, giao thức và thuật toán cụ thể.
Ví dụ
Running `dig DNSKEY cloudflare.com` returns the public keys Cloudflare uses to sign its DNSSEC records — validators use these keys to verify all other DNSSEC signatures in the zone.