Root Zone DNSSEC and Infrastructure Radar
Security DashboardTechnical health monitor for the global Domain Name System root. Tracks cryptographic DNSSEC signing rates, algorithm modernization (RSA vs ECDSA vs Ed25519), and operational deployments across the 13 authoritative root server constellations.
| Algorithm Name | IANA Number | Cryptographic Family | Adoption Share | Security Status |
|---|---|---|---|---|
| ECDSAP256SHA256 | 13 | Elliptic Curve (NIST P-256) | 62.4% | Recommended |
| RSASHA256 | 8 | RSA (2048-bit) | 34.1% | Acceptable |
| ED25519 | 15 | Edwards-curve (Curve25519) | 2.8% | Modern Standard |
| Legacy RSASHA1 / Other | 5 / 7 | SHA-1 based | 0.7% | Deprecated |
Authoritative Root Server Constellations (A through M)
Root Server System Advisory Committee (RSSAC)| Root Letter | Operating Organization | IPv4 Address | IPv6 Address | Autonomous System | Global Anycast Nodes |
|---|---|---|---|---|---|
| A.ROOT-SERVERS.NET | Verisign, Inc. | 198.41.0.4 | 2001:503:ba3e::2:30 | AS36622 | 300+ |
| B.ROOT-SERVERS.NET | USC-ISI | 199.9.14.201 | 2001:500:200::b | AS394380 | 12 |
| C.ROOT-SERVERS.NET | Cogent Communications | 192.33.4.12 | 2001:500:2::c | AS2149 | 25+ |
| D.ROOT-SERVERS.NET | University of Maryland | 199.7.91.13 | 2001:500:2d::d | AS10886 | 180+ |
| E.ROOT-SERVERS.NET | NASA Ames Research Center | 192.203.230.10 | 2001:500:a8::e | AS2153 | 100+ |
| F.ROOT-SERVERS.NET | Internet Systems Consortium | 192.5.5.241 | 2001:500:2f::f | AS3557 | 250+ |
| G.ROOT-SERVERS.NET | US Department of Defense (DISA) | 192.112.36.4 | 2001:500:12::d0d | AS5927 | 15 |
| H.ROOT-SERVERS.NET | US Army Research Lab | 198.97.190.53 | 2001:500:1::53 | AS1508 | 20+ |
| I.ROOT-SERVERS.NET | Netnod (Autonomica) | 192.36.148.17 | 2001:7fe::53 | AS8674 | 70+ |
| J.ROOT-SERVERS.NET | Verisign, Inc. | 192.58.128.30 | 2001:503:c27::2:30 | AS26415 | 350+ |
| K.ROOT-SERVERS.NET | RIPE NCC | 193.0.14.129 | 2001:7fd::1 | AS25152 | 90+ |
| L.ROOT-SERVERS.NET | ICANN | 199.7.83.42 | 2001:500:9f::42 | AS20144 | 180+ |
| M.ROOT-SERVERS.NET | WIDE Project | 202.12.27.33 | 2001:dc3::35 | AS7506 | 40+ |
DNSSEC Chain of Trust Architecture
DNSSEC establishes trust through cryptographic digital signatures. The DNS root contains the Key Signing Key (KSK), which cryptographically signs Delegation Signer (DS) records for each TLD registry. When a recursive resolver validates a domain name, it traces cryptographic hashes up to the root trust anchor, preventing DNS spoofing, man-in-the-middle cache poisoning, and unauthorized redirection.
The Shift to Modern Elliptic Curve (ECDSA)
Over 60% of top-level domains have migrated from legacy 2048-bit RSA to ECDSA P-256 (Algorithm 13). Elliptic curve algorithms provide equivalent cryptographic security with dramatically smaller key and signature sizes, substantially reducing DNS UDP packet fragmentation and mitigating DNS amplification attack vectors.