Root Zone DNSSEC and Infrastructure Radar

Security Dashboard

Technical health monitor for the global Domain Name System root. Tracks cryptographic DNSSEC signing rates, algorithm modernization (RSA vs ECDSA vs Ed25519), and operational deployments across the 13 authoritative root server constellations.

Root DNSSEC Status SIGNED 2048-bit RSA KSK-2017
TLDs Signed with DS 1,418 / 1,438 98.6% adoption
Leading Algorithm ECDSA (P-256) Algorithm 13 (62%)
Root Server Letters 13 A through M
Anycast Sites Worldwide 1,700+ Distributed nodes
IPv6 Glue Reachability 100% All root letters
DNSSEC Signing Algorithm Distribution Across Top Level Domains Cryptographic standards mandated under RFC 8624
Algorithm Name IANA Number Cryptographic Family Adoption Share Security Status
ECDSAP256SHA256 13 Elliptic Curve (NIST P-256) 62.4% Recommended
RSASHA256 8 RSA (2048-bit) 34.1% Acceptable
ED25519 15 Edwards-curve (Curve25519) 2.8% Modern Standard
Legacy RSASHA1 / Other 5 / 7 SHA-1 based 0.7% Deprecated

Authoritative Root Server Constellations (A through M)

Root Server System Advisory Committee (RSSAC)
Root Letter Operating Organization IPv4 Address IPv6 Address Autonomous System Global Anycast Nodes
A.ROOT-SERVERS.NET Verisign, Inc. 198.41.0.4 2001:503:ba3e::2:30 AS36622 300+
B.ROOT-SERVERS.NET USC-ISI 199.9.14.201 2001:500:200::b AS394380 12
C.ROOT-SERVERS.NET Cogent Communications 192.33.4.12 2001:500:2::c AS2149 25+
D.ROOT-SERVERS.NET University of Maryland 199.7.91.13 2001:500:2d::d AS10886 180+
E.ROOT-SERVERS.NET NASA Ames Research Center 192.203.230.10 2001:500:a8::e AS2153 100+
F.ROOT-SERVERS.NET Internet Systems Consortium 192.5.5.241 2001:500:2f::f AS3557 250+
G.ROOT-SERVERS.NET US Department of Defense (DISA) 192.112.36.4 2001:500:12::d0d AS5927 15
H.ROOT-SERVERS.NET US Army Research Lab 198.97.190.53 2001:500:1::53 AS1508 20+
I.ROOT-SERVERS.NET Netnod (Autonomica) 192.36.148.17 2001:7fe::53 AS8674 70+
J.ROOT-SERVERS.NET Verisign, Inc. 192.58.128.30 2001:503:c27::2:30 AS26415 350+
K.ROOT-SERVERS.NET RIPE NCC 193.0.14.129 2001:7fd::1 AS25152 90+
L.ROOT-SERVERS.NET ICANN 199.7.83.42 2001:500:9f::42 AS20144 180+
M.ROOT-SERVERS.NET WIDE Project 202.12.27.33 2001:dc3::35 AS7506 40+

DNSSEC Chain of Trust Architecture

DNSSEC establishes trust through cryptographic digital signatures. The DNS root contains the Key Signing Key (KSK), which cryptographically signs Delegation Signer (DS) records for each TLD registry. When a recursive resolver validates a domain name, it traces cryptographic hashes up to the root trust anchor, preventing DNS spoofing, man-in-the-middle cache poisoning, and unauthorized redirection.

The Shift to Modern Elliptic Curve (ECDSA)

Over 60% of top-level domains have migrated from legacy 2048-bit RSA to ECDSA P-256 (Algorithm 13). Elliptic curve algorithms provide equivalent cryptographic security with dramatically smaller key and signature sizes, substantially reducing DNS UDP packet fragmentation and mitigating DNS amplification attack vectors.