https://stats.sidnlabs.nl/en/DNS | DNSSEC | Dataset | IP | Network
Historic datasets (from 2014 onwards) for the .nl TLD. Datasets are available in JSON format.
Datasets cover information about:
- Domain Names
- Query Type
- Response Codes
- IPv6 Support
- Number of IP addresses
- Validating Resolvers
- Popular Networks
- Port Randomness
- Validating Queries
- Used Algorithms
https://stats.labs.apnic.net/Autonomous System | BGP | DNS | DNSSEC | Dataset | IP
APNIC gathers many statistics and offers them on their website. However, they provide way more data than it might initially look like, since many of the datasets are not linked from their main page.
DNS | DNSSEC
Contains lists for DNS servers, libraries, tools, and other resources.
List of maintained and unmaintained DNS servers, including descriptions for each of them.
Short overview of open-source projects for authoritative and recursive servers and development libraries.
https://www.knot-dns.cz/benchmark/DNS | DNSSEC | Dataset
The website is an ongoing project by Knot DNS to measure the performance of various DNS servers. Four open-source servers are tested, namely BIND, Knot DNS, NSD, and PowerDNS. The benchmark includes different zone configurations matching to root zones, TLD zones, or hosting zones as well as different DNSSEC configurations.
https://dnsprivacy.org/DNS | DNSSEC | Dataset | TLS
The DNS Privacy Project aims to improve privacy for users on the Internet.
The project is split into different groups working on DNS privacy:
The project focuses mostly on DNS over TLS. They provide overviews for the implementation status, configuration for test servers, and ongoing server monitoring which features they provide.
DNS | DNSSEC | Dataset | Network | Tool
Browser-based DNS resolver quality measurement tool. Uses the browser to generate many resolver queries and tests for features they should have, such as EDNS support, IPv6, QNAME Minimisation, etc.
This test is also available as a CLI tool: https://github.com/DNS-OARC/cmdns-cli
Analyze DNSSEC deployment for a zone and show errors in the configuration.
Gives an overview of DNSSEC delegations, response sizes, and name servers.
The website has an online test, which performs DNS lookups. These DNS lookups test if certain resource records are overwritten in the cache. The tool can then determine what DNS software is used, where the server is located, how many caches there are, etc.
Test name server of zones for correct EDNS support.
Shows the trust dependencies in DNS. Given a domain name it can show how zones delegate to each other and why. The delegation is done between IP addresses and zones.
The project used to monitor the first root KSK key rollover. Now it contains the paper "Roll, Roll, Roll your Root: A Comprehensive Analysis of the FirstEver DNSSEC Root KSK Rollover" describing the experiences of the first root KSK rollover
Additionally, it includes a tester for DNSSEC algorithm support, which shows the algorithms supported by the currently used recursive resolver. It provides statistics about support for DNSSEC algorithms. It has a web based test to test your own resolver and provides a live monitoring using the RIPA Atlas.
DNSSEC algorithms resolver test
https://www.internetsociety.org/deploy360/dnssec/maps/DNS | DNSSEC | Dataset | Network
The Internet Society published maps showing the distribution of IPv6 support worldwide. The maps are available also with historic data, but are only updated sporadically. More current maps and CSV files are available on the mailing list.
https://rick.eng.br/dnssecstat/DNS | DNSSEC | Dataset | Network
Regularly updated reports about current DNSSEC deployment. Contains information per TLD and global distribution.
https://www.dnssek.info/DNS | DNSSEC | Dataset
The website keeps track of all DNSSEC keys in the top level domains (TLDs) and informs when the signatures are about to expire. The time before some RRSIGs expire is color coded. It also shows error which happened during validation.
https://powerdns.org/hello-dns/DNS | DNSSEC | Tutorial
Hello DNS is a project to write a easy to read/understand summary of the DNS specification. It provides an entrypoint to understand DNS given that the full DNS specification is easily 2000 pages in size.
https://ithi.research.icann.org/metrics.htmlDNS | DNSSEC | Dataset | Network
ICANN tracks the general health of the DNS ecosystem and related ecosystems. The data is updated irregularly, but historic data is available. The collected data covers eight major topics:
- M1: inaccuracy of Whois Data
- M2: Domain Name Abuse
- M3: DNS Root Traffic Analysis
- M4: DNS Recursive Server Analysis
- M5: Recursive Resolver Integrity
- M6: IANA registries for DNS parameters
- M7: DNSSEC Deployment.
- M8: DNS Authoritative Servers Analysis
Each topic has too many sub categories to list here.
https://ianix.com/pub/dnssec-outages.htmlDNS | DNSSEC | Dataset
The website collects major outages caused by broken DNSSEC deployments in the wild. It tracks root and TLD errors and some selected websites. Each outage is timestamped and has some description about the problem. The entries contain information from the Verisign DNSSEC debugger and DNSViz.
https://workbench.sidnlabs.nl/DNS | DNSSEC
The DNS workbench is a testbed which allows experimentation how different authoritative DNS servers answer to queries.
It covers five open-source authoritative servers, namely Bind9, Knot, NSD4, PowerDNS, and Yadifa. The workbench contains zones to test the support for many different resource record (RR) types, DNSSEC validation and how invalid zones are managed, delegations, zone transfers, and potentially more.
Find the project on GitHub.
https://blog.apnic.net/2023/01/17/subdomain-enumeration-with-dnssec/DNS | DNSSEC | Tutorial
The blog post about Subdomain Enumeration in the APNIC blog provides a great overview of the techniques, defenses, and tools for it. Subdomain enumeration is the act of learning available subdomains in a zone using DNSSEC. This is with
NSEC records and somewhat harder with
NSEC3, due to hashing of names. The blog goes explains how online signing can combat subdomain enumeration, using the white lies or the black lies strategies. Lastly, it links to tools for performing these attacks.
https://observatory.research.icann.org/tld-apex-history/DNS | DNSSEC | Dataset | IP | Network
The TLD Apex History is an ICANN project to gather DNSSEC related records for all TLDs.
Further information about the project can be found in this presentation.
https://dnsthought.nlnetlabs.nl/DNS | DNSSEC | Dataset | Network
Dnsthought list many statistics about the resolvers visible to the .nl-authoritative name servers. The data is gathered from the RIPE Atlas probes. There is a dashboard which only works partially.
Raw data access is also available.