Side effect of DNSSEC: an increase of DS queries

The information below is for an old version of the document
Document Type Expired Internet-Draft (individual)
Author Kazunori Fujiwara 
Last updated 2014-01-16 (latest revision 2013-07-15)
Stream (None)
Expired & archived
pdf htmlized bibtex
Additional Resources
Stream Stream state (No stream defined)
Consensus Boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


An increase of periodic DS queries is observed at top level domain (TLD) DNS servers. Almost all of periodic DS queries are queries for unsigned delegations. The reason of the increase is low NCACHE TTL value and DS nonexistence. This phenomena is DNSSEC protocol and DNS parameter issue. DS queries will increase as DNSSEC validators will increase.


Kazunori Fujiwara (

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)