Standards & RFCs

Reference

Key IETF standards, RFCs, and BCPs that define DNS root server operations, resolver behavior, protocol mechanics, and security extensions.

15+Referenced RFCsCore DNS specifications
6CategoriesCore · Operations · Resolver · Security · Terminology · Anycast
DNSSECSecurity standardsRFC 4033 / 4034 / 4035 / 5011
IETFStandards bodyInternet Engineering Task Force

Core DNS

Foundational specifications that define the Domain Name System

RFC 1034Standard

Domain Names — Concepts and Facilities

Defines the fundamental concepts of the DNS: the domain name space, resource records, name servers, and resolvers. Establishes the hierarchical namespace structure and delegation model that root servers sit at the top of.

STD 13Nov 1987Read RFC
RFC 1035Standard

Domain Names — Implementation and Specification

Companion to RFC 1034. Specifies the DNS message format, transport (UDP/TCP on port 53), resource record wire format, master file format, and the operational details of name servers and resolvers.

STD 13Nov 1987Read RFC

Root Server Operations

Standards governing root name service requirements and local root operation

RFC 7720BCP 40

DNS Root Name Service Protocol and Deployment Requirements

Defines the protocol and deployment requirements for the DNS root name service. Specifies that root servers must support both UDP and TCP, EDNS(0), and DNSSEC. Obsoletes RFC 2870.

Dec 2015Read RFC
RFC 8806Informational

Running a Root Server Local to a Resolver

Describes how to configure a recursive resolver to serve the root zone locally via zone transfer, reducing latency and improving privacy for root queries. Covers AXFR/IXFR from distribution servers.

Jun 2020Read RFC
RFC 2826BCP 4

IAB Technical Comment on the Unique DNS Root

States the Internet Architecture Board's position that there must be a single authoritative root for the public DNS. Establishes the principle of a unique root as fundamental Internet architecture.

May 2000Read RFC

Resolver Behavior

Standards for how DNS resolvers interact with the root and name server infrastructure

RFC 9609BCP 209

DNS Resolver Priming

Describes the priming process by which a DNS resolver initializes its root server cache. Specifies that resolvers must send a priming query for ". NS" and process the response to populate root NS records and glue.

Aug 2024Obsoletes RFC 8109Read RFC
RFC 5765Proposed Standard

Security Implications of Using the Data Encryption Standard (Informational; root resolver context)

Note: This slot reserved for future resolver-specific RFCs as the IETF publishes updates. The DNS resolver ecosystem continues to evolve with new best practices.

DNS Security (DNSSEC)

Extensions providing authentication and integrity for DNS data

RFC 4033Proposed Standard

DNS Security Introduction and Requirements

Introduces the DNS Security Extensions (DNSSEC), explaining the threat model, design goals, and overall architecture. Describes the trust chain from root to leaf zones using signed delegation.

Mar 2005DNSSEC-bisRead RFC
RFC 4034Proposed Standard

Resource Records for the DNS Security Extensions

Defines the DNSSEC resource record types: DNSKEY (public keys), RRSIG (signatures), NSEC (authenticated denial of existence), and DS (delegation signer). These records form the cryptographic backbone of DNSSEC.

Mar 2005DNSSEC-bisRead RFC
RFC 4035Proposed Standard

Protocol Modifications for the DNS Security Extensions

Specifies the modifications to DNS protocol processing for DNSSEC. Covers signature validation, chain of trust construction, handling of the AD and CD bits, and requirements for security-aware resolvers and servers.

Mar 2005DNSSEC-bisRead RFC
RFC 5011Standard

Automated Updates of DNS Security (DNSSEC) Trust Anchors

Defines the mechanism for automated trust anchor rollover using the "hold-down" timer approach. Critical for root key rollovers — allows validators to track changes to the root zone KSK without manual intervention.

Sep 2007Root KSK rolloverRead RFC

DNS Terminology

Authoritative definitions for DNS concepts and components

RFC 9499BCP 219

DNS Terminology

The authoritative glossary of DNS terms. Defines over 100 terms including root server, authoritative server, recursive resolver, stub resolver, zone, delegation, glue records, and many more. Obsoletes RFC 8499.

Mar 2024Obsoletes RFC 8499Read RFC

Anycast

Standards for IP anycast as used by root server deployments

RFC 4786BCP 126

Operation of Anycast Services

Describes operational considerations for deploying anycast services, which is the primary distribution method for root server instances. Covers routing stability, catchment areas, and monitoring challenges.

Dec 2006Read RFC
RFC 7094Informational

Architectural Considerations of IP Anycast

Analyzes the architectural implications of IP anycast for Internet services. Discusses how anycast interacts with TCP, DNSSEC, and geolocation, with direct relevance to how root server operators distribute their service globally.

Jan 2014Read RFC

IANA

The Internet Assigned Numbers Authority manages the root zone and maintains the authoritative list of root server operators and service addresses.

RSSAC

The Root Server System Advisory Committee advises ICANN on operational matters relating to the root name server system. Publishes advisories and measurements.

IETF Datatracker

The IETF's document database and tracking system. Search for any RFC, Internet-Draft, or working group document related to DNS and root server operations.

Download Root Server Data

Get structured root server data in JSON, CSV, and YAML formats for your projects and reference builds.

View Data