Profile Picture of Joel Söderman
Applied for a new gTLD? It’s time to get DNSSEC right

Applied for a new gTLD? It’s time to get DNSSEC right

If your organisation applied for a new generic Top-Level Domain (gTLD) in ICANN's 2026 round, submitting the application was only the beginning.

As applications move through evaluation towards contracting and, ultimately, delegation, attention turns to the infrastructure that will keep each new gTLD secure and available. One essential part of that is Domain Name System Security Extensions (DNSSEC).

Under ICANN's new gTLD Program requirements, DNSSEC isn't optional. All new gTLDs must operate a DNSSEC-signed TLD zone.

But what does that mean in practice and what should prospective gTLD applicants be thinking about now?

What is DNSSEC and why is it important?

The DNS is used by every Internet application to transform human-readable names such as www.netnod.se into the numeric string (known as the IP address) for that domain.

Traditional DNS has a vulnerability: it wasn't designed to verify that the information it receives is genuine. This means an attacker could potentially manipulate a DNS response and redirect users away from your legitimate gTLD domains to somewhere they didn't intend to go.

DNSSEC adds that verification. Using cryptographic signatures, DNSSEC allows DNS resolvers to check that the information really comes from the right source and hasn't been changed along the way. Put simply, DNSSEC helps ensure users are directed to the genuine domains and services they intended to reach.

For gTLD operators, this is particularly important. Your gTLD sits between the DNS root and every domain registered under it. If that link in the chain of trust fails, users may be unable to reach those domains. Keeping DNSSEC secure and reliable is therefore a critical part of running a gTLD.

What does running DNSSEC actually involve?

DNSSEC isn't something you configure once at launch and then forget about. Once your gTLD is live, it becomes an ongoing operational responsibility.

At the heart of this is key management. The cryptographic keys used by DNSSEC need to be securely generated, stored, used, and monitored. They also need to be periodically rotated according to carefully controlled procedures.

Registry operators also need robust processes for handling DNSSEC information for domains beneath their gTLD as well as documented operational and security procedures.

This is why the choice of your DNSSEC RSP matters.

What should you look for in a DNSSEC provider?

For organisations planning the infrastructure behind a new gTLD, there are three areas to consider:

  • Track record: does the provider have extensive experience operating DNSSEC-signed infrastructure reliably at scale?
  • Key management: are cryptographic keys generated, stored and managed using secure, documented and auditable processes?
  • Operational resilience: are monitoring, redundancy and incident procedures designed to keep the service running when something goes wrong?

That last point is important because mistakes in DNSSEC operations can have immediate consequences. An expired signature, incorrectly managed key change or broken chain of trust can cause validating DNS resolvers to reject otherwise legitimate DNS information. To users, the affected domain or service simply stops working.

At gTLD level, where potentially large numbers of domains depend on your infrastructure, flawless DNSSEC operations are essential.

Build in DNSSEC from the start

DNSSEC should be part of your gTLD’s infrastructure from the beginning, not something added later. This makes it easier to put the right security, key management and operational processes in place before your gTLD goes live.

When DNSSEC works properly, users won’t notice it. But behind the scenes, it means they can trust the DNS information that directs them to the domains and services under your gTLD.

Review your RSP choice

Choosing from ICANN’s list of evaluated Registry Service Providers (RSPs) confirms that your provider has met ICANN’s technical requirements. But applicants should still carry out their own due diligence particularly when choosing the provider that will operate their critical DNS and DNSSEC infrastructure.

If you haven’t yet named an RSP, or want to review your existing choice, there is still time to do so. Applicants can select an RSP or request a change through ICANN’s Application Change Request process.

When making that decision, consider the provider’s operational experience, resilience, security practices and long-term DNSSEC expertise.

Netnod: the trusted experts for DNS and DNSSEC

Netnod is an ICANN-approved RSP for DNS and DNSSEC with decades of experience operating critical DNS infrastructure. We provide DNS and DNSSEC services to major ccTLDs and operate i-root, one of the Internet’s 13 root name server systems, with more than 20 years of 100% availability.

Our DNSSEC experience goes back to its earliest deployments. In 2005, Netnod’s infrastructure helped .se become the first TLD in the world to deploy DNSSEC. Our experts also remain actively involved in DNS development through the IETF — from co-authoring the requirements for the DNS root name service (RFC 7720) to contributing to ongoing work around multi-signer DNSSEC.

This combination of proven operations and deep technical expertise underpins the DNS and DNSSEC services we provide to TLD operators worldwide. 

Planning DNS and DNSSEC for your new gTLD? Talk to Netnod about the resilience, security and long-term DNSSEC expertise behind our ICANN-approved RSP services.

 

Related blog articles

Show all blog articles