Primary Domain
DNS
Within the Primary Domain facet, DNS intelligence groups reporting by primary domain so readers can follow a focused area of internet infrastructure, governance, connectivity markets, or digital capital. The page brings together related articles, public evidence, institutions, companies, people, regional exposure, operating dependencies, and market context that may otherwise sit across separate category pages. It explains the domain, the likely actor class, the market or governance context, and the source material readers should use when comparing signals. Operators, analysts, and governance readers can see how the same domain appears across events, profiles, market shifts, public-source evidence, regional dependencies, and longer-cycle infrastructure decisions over time.

IETF
The algorithm has a number. The resolver may still say no
RFC 9563 gives SM2 signatures and SM3 digests stable DNSSEC identifiers. That solves an addressing problem. It does not establish IETF consensus, cryptographic suitability, implementation support, an authenticated delegation or a successful DNS answer.

IETF
The Backup Nameserver Answered. The Cached Key Did Not Fit: RFC 8901
A second authoritative DNS provider can keep answering after the first one fails and still leave validating resolvers without an acceptable answer. RFC 8901 shows why DNSSEC redundancy is a synchronization contract across signers, not a count of nameservers.

History
Gihan Dias and the Two Names Sri Lanka Added to the Root
The smallest-looking part of a national network can expose its largest unfinished business. For Sri Lanka, two names in the DNS root showed that connecting a country and letting it recognise itself online were separate engineering tasks.

CASE FILE
When a BIND Fix Is Not Yet a Repair
A resolver vulnerability becomes an institutional accountability test when the patch is available but the evidence of recovery is not. ISC’s public record establishes how two BIND failures can turn hostile DNS input into an availability risk—and identifies a remediation…

IETF
James Gould and the Redaction Signal That Is Not Policy Proof
An empty place in an RDAP response can mean that no value exists, that a value was withheld, or that the question exposed a shape the server chose not to acknowledge. RFC 9537 gives one of those absences a machine-readable explanation. James Gould’s work on the specification…

CASE FILE
A Public Sponsor for a Private Namespace
An enterprise can need outside confirmation of an internal DNS arrangement without wanting to publish its internal directory. RFC 9704 offers a way to separate those disclosures. The difficult decisions concern what remains visible, how much authority one approval covers, and who…

IETF
Suzanne Woolf and the Server Label That Is Not a Machine Identity
A DNS reply can carry a label for the server that produced it. That sounds like identity until anycast, operator-defined bytes and hop-by-hop scope are allowed back into the picture. Suzanne Woolf’s work on the requirements behind NSID offers a more useful interpretation: the…

IETF
Sara Dickinson and the Resolver Promise Encryption Cannot Prove
The padlock beside a DNS resolver name is reassuring because it proves something useful: the client has protected its conversation on the way to a particular service. It is also dangerously easy to ask that icon to prove the rest. Sara Dickinson’s co-authored RFC 8932 follows the…

ICANN
Allison Mankin and the Name-Collision Sample That Could Not Prove Its Cause
A root server can record a query for a private-looking name with great precision. The record still cannot say which application produced it, who owns the broken dependency, how many users rely on it or what a future delegation would harm. Allison Mankin’s work on RFC 8023 helps…

CASE FILE
The Key Was Known. It Was Not Yet Trusted
A self-signed DNS update arrives at a parent carrying a new key and an instruction to delete the old one. The signature proves that somebody holds the new private key. It does not prove that this somebody may change the child's delegation. As DNSOP's 7 September Last Call reaches…

CASE FILE
The Final Dot Vanished. The Trust Boundary Moved with It
Two hostnames can lead DNS to the same node and still lead an application to different security decisions. As the DNSOP Working Group closes its 7 September Last Call on guidance for bringing domain names into applications, a recent curl flaw gives the abstract warning a concrete…

IETF
QNAME Minimisation Is a Query-Sequence Contract, Not a Privacy Switch
A resolver may advertise QNAME minimisation while exposing very different names, costs and failure modes from one lookup to the next. The feature matters only when operators can reconstruct the bounded sequence produced by delegation knowledge, cache state and negative proofs.

CASE FILE
DNS Received the Hint. The Parent Still Had to Decide: RFC 9859’s Delegation Boundary
RFC 9859 can make delegation maintenance faster. It cannot make a notification into a parent-side decision, or turn a received response into proof that DNSSEC or delegation state has changed.
