dns.pizza research

The State of DNSSEC 2026: the security feature the web quietly refused to deploy

We validated DNSSEC on 96,917 domains of the Tranco top 100,000. 8.2% have a chain a resolver can actually verify — and a quarter of the zones that did turn signing on never finished the job.

Published August 1, 2026 · data collected July 2026August 2026 · download the data

8.2%

have DNSSEC a resolver can validate

89%

publish no DNSSEC at all

25.5%

of zones that signed never delegated (no DS record)

35

domains are actively broken for validating resolvers

Key findings

  1. Nine in ten top domains are unsigned. 86,216 of 96,917 domains (89%) publish no DNSSEC records whatsoever. The protocol was standardised in 2005; twenty-one years later the overwhelming default is still an unauthenticated zone.
  2. A quarter of the zones that signed never finished. 2,730 domains publish DNSKEY records but have no DS record in their parent zone — 25.5% of the 10,701 zones that went to the trouble of generating keys. Without the DS handoff at the registrar, resolvers treat the zone as unsigned: all of the operational cost, none of the protection.
  3. Registry policy explains almost everything. The registries that subsidised or mandated signing are an order of magnitude ahead: .nl at 52.1%, .cz at 51.2%, .se at 33.8% — against .com's 6.8% across 45,063 domains. .gov leads outright at 60.7%, which is what a compliance mandate buys. Adoption tracks who is paying and who is requiring — not domain owners independently discovering the benefit.
  4. Being a big site barely helps. The top 1,000 validate at 10.8% versus 8% in the 10k–100k tail — a spread of 2.8 points. Unlike TLS, where the largest sites led the way, DNSSEC has no popularity gradient worth the name.
  5. Where it is deployed, it mostly works — and the crypto is modern. Only 35 domains (0.04%) are bogus, meaning validating resolvers refuse to answer for them. Among signed domains whose DS record we captured, 75.5% use ECDSA P-256, the ECDSA curve that made one-click signing cheap. The legacy tail is small but real: 411 still anchor on a SHA-1 DS digest and 156 on deprecated RSA/SHA-1 algorithms.
  6. Most signed zones are walkable. 63.6% of validating domains use plain NSEC rather than hashed NSEC3, which lets anyone enumerate every name in the zone. Paired with the ECDSA dominance above, that is the fingerprint of automated one-click signing at large managed DNS hosts rather than hand-rolled deployments.

DNSSEC state by popularity tier

Share of domains in each Tranco rank tier. Signing without delegating leaves a zone in the same place as never signing at all.

Source: dns.pizza DNSSEC validations · snapshot August 1, 2026

Adoption by TLD

The 15 highest-adoption TLDs of the 58 with at least 200 measured domains, plus .com for scale. All 58 are in the table below.

Source: dns.pizza DNSSEC validations · snapshot August 1, 2026

The bottom of the table

In some registries adoption does not merely trail — it is absent. .kr (0% of 270), .ir (0% of 410), .tr (0.3% of 318) and .to (0.5% of 201) sit at or within a rounding error of zero. Where a registry neither requires DNSSEC nor makes it free and one-click at the registrar, essentially nobody enables it on their own.

The numbers

SegmentDomainsValidatesSigned, no DSUnsignedBroken
All domains96,9178.2%2.8%89%0.04%
Top 1,00096310.8%0.7%88.5%0%
1,001 – 10,0008,93610.2%2.5%87.2%0.04%
10,001 – 100,00087,0188%2.9%89.1%0.04%
.gov42760.7%2.1%37.2%0%
.nl62952.1%4.1%43.7%0%
.cz38151.2%3.7%45.1%0%
.se30233.8%1.3%64.9%0%
.ch24824.6%2%73.4%0%
.be23818.5%2.1%79.4%0%
.br1,35517.2%3.7%79%0.07%
.tw31216.3%4.2%79.5%0%
.hu26915.6%5.2%79.2%0%
.fi21615.3%2.3%82.4%0%
.id38013.2%11.6%75.3%0%
.eu33312%2.7%85.3%0%
.io1,85611.2%2.9%85.9%0%
.edu81010.9%1.1%88%0%
.de1,73510.8%1.7%87.5%0%
.app39410.4%4.1%85.5%0%
.us23210.3%2.6%86.6%0.43%
.fr95510.1%1.8%88.2%0%
.es5309.4%1.3%89.2%0%
.org4,0399.3%3.5%87.2%0%
.ca4469.2%0.9%89.9%0%
.jp1,7208.7%1.9%89.5%0%
.top2218.6%3.6%86.9%0.9%
.in1,2078.4%2.9%88.6%0.08%
.cloud3448.1%2.9%89%0%
.net6,2777.7%2%90.2%0.11%
.at2287.5%1.3%91.2%0%
.info4056.9%2%91.1%0%
.com45,0636.8%2.7%90.5%0.02%
.pl7416.6%3.1%90.3%0%
.me4256.6%4.2%89.2%0%
.au5045.8%2%92.3%0%
.co8145.7%3.9%90.4%0%
.ro2745.5%3.6%90.1%0.73%
.uk1,2885%1.3%93.6%0%
.cl2005%5.5%89%0.5%
.ua3674.9%3.5%91.6%0%
.ai4114.6%6.1%89.3%0%
.live2194.6%1.8%93.6%0%
.gr2944.4%2.7%92.9%0%
.mx2744.4%3.6%91.6%0.36%
.tv5024.2%2.6%93%0.2%
.za2234%1.8%94.2%0%
.cc3293.6%2.7%93.6%0%
.xyz4523.5%2.4%94%0%
.vn2883.5%5.9%90.6%0%
.cn9163.1%0.5%96.2%0.22%
.pro2333%2.6%94.4%0%
.site2092.9%2.9%93.3%0.96%
.online2262.7%2.7%94.7%0%
.biz3322.1%1.2%96.7%0%
.ar2631.9%4.6%93.5%0%
.ru3,6691.6%3.1%95.3%0%
.it8261.5%2.3%96.2%0%
.to2010.5%3.5%96%0%
.tr3180.3%6%93.7%0%
.ir4100%3.4%96.3%0.24%
.kr2700%1.5%98.5%0%
Download the full dataset (CSV)

DS algorithms in use

Share of the 7,700 validating domains whose DS record we captured.

ECDSA P-2565,81375.5%
RSA/SHA-2561,57720.5%
RSASHA1-NSEC3-SHA11021.3%
RSA/SHA-512570.7%
RSA/SHA-1540.7%
Ed25519490.6%
ECDSA P-384480.6%

Denial of existence

Share of the 7,936 validating domains. NSEC lets anyone walk the zone; NSEC3 hashes the names first.

NSEC (zone is walkable)5,04963.6%
NSEC3 (hashed denial)2,67833.7%
No denial-of-existence records seen2092.6%

Methodology

dns.pizza continuously validates DNSSEC while generating domain intelligence reports across the Tranco top 100,000. Each check walks the chain of trust from the root down over DNS-over-HTTPS and, separately, asks a validating resolver for its own verdict (the AD flag, plus a checking-disabled probe to tell a validation failure apart from a broken zone). This report aggregates the latest check per domain — 96,917 conclusive results measured between July 7, 2026 and August 1, 2026.

One vote per domain (latest check only). The four states partition the corpus exactly: validates (a validating resolver confirms the chain), signed but not delegated (DNSKEY present, no DS record in the parent — resolvers treat it as unsigned), unsigned, and broken (signed but failing validation, so resolvers SERVFAIL it). Checks whose DS/DNSKEY lookups failed are recorded as indeterminate and excluded from every denominator — an unreachable record is unknown, not absent. That was 4,553 of 101,470 observations (4.5%).

Only observations made after July 7, 2026 are included. Before that date our validator could not query DS and DNSKEY record types at all and silently recorded every domain as unsigned; those results are excluded rather than published, because they measure our own bug and not the internet.

Per-TLD rows require at least 200 conclusive domains, which yields 58 TLD rows. The gate excludes 9,887 domains across 618 smaller TLDs (10.2% of the corpus) from the per-TLD table; they remain in the overall and per-tier numbers. Algorithm shares are taken over the 7,700 validating domains whose DS record we captured, not all 7,936 — some domains validate at the resolver while our own DS fetch returns nothing parseable.

Limitations: the corpus is the top-ranked slice of the web (Tranco aggregates several popularity signals; it is not a literal visit count), so absolute adoption rates will read higher than the web at large. Per-country TLD figures reflect the domains popular enough to rank, not every registration in that registry. DNSSEC state is measured at the organizational domain only, and a zone that validates today can break tomorrow — signature expiry is the most common cause.

The data is free to cite and reuse (CC BY 4.0, credit "dns.pizza"). For questions or the raw per-domain data, get in touch.

Is your zone actually delegated?

Check whether your DNSSEC chain validates — or whether you are one of the 2,730 publishing keys nobody can verify.

Validate your DNSSEC