Skip to main content

Primary Domain

DNS

Within the Primary Domain facet, DNS intelligence groups reporting by primary domain so readers can follow a focused area of internet infrastructure, governance, connectivity markets, or digital capital. The page brings together related articles, public evidence, institutions, companies, people, regional exposure, operating dependencies, and market context that may otherwise sit across separate category pages. It explains the domain, the likely actor class, the market or governance context, and the source material readers should use when comparing signals. Operators, analysts, and governance readers can see how the same domain appears across events, profiles, market shifts, public-source evidence, regional dependencies, and longer-cycle infrastructure decisions over time.

Two amber algorithm tokens feed separate DNSSEC implementation, delegation, policy and validation chambers before a cyan result path reaches an application endpoint.

IETF

The algorithm has a number. The resolver may still say no

RFC 9563 gives SM2 signatures and SM3 digests stable DNSSEC identifiers. That solves an addressing problem. It does not establish IETF consensus, cryptographic suitability, implementation support, an authenticated delegation or a successful DNS answer.

Sep 27, 2026
Two independent DNSSEC signers publish the same active key set while a resolver changes providers during failover.

IETF

The Backup Nameserver Answered. The Cached Key Did Not Fit: RFC 8901

A second authoritative DNS provider can keep answering after the first one fails and still leave validating resolvers without an acceptable answer. RFC 8901 shows why DNSSEC redundancy is a synchronization contract across signers, not a count of nameservers.

Sep 23, 2026
AI editorial portrait of Gihan Dias beside two branching DNS structures representing Sri Lanka’s Sinhala and Tamil domains

History

Gihan Dias and the Two Names Sri Lanka Added to the Root

The smallest-looking part of a national network can expose its largest unfinished business. For Sri Lanka, two names in the DNS root showed that connecting a country and letting it recognise itself online were separate engineering tasks.

Sep 12, 2026
Abstract DNS infrastructure with branching query paths, redundant authoritative servers and a contained signal anomaly being repaired.

CASE FILE

When a BIND Fix Is Not Yet a Repair

A resolver vulnerability becomes an institutional accountability test when the patch is available but the evidence of recovery is not. ISC’s public record establishes how two BIND failures can turn hostile DNS input into an availability risk—and identifies a remediation…

Sep 10, 2026
AI editorial portrait of James Gould beside abstract structured registry-response panes that preserve distinct absent, empty, partial and replacement states

IETF

James Gould and the Redaction Signal That Is Not Policy Proof

An empty place in an RDAP response can mean that no value exists, that a value was withheld, or that the question exposed a shape the server chose not to acknowledge. RFC 9537 gives one of those absences a machine-readable explanation. James Gould’s work on the specification…

Sep 7, 2026
An opaque canopy covers amber rooms beside a visible blue marker and copper paths, evoking private DNS names with deliberately public authorization information.

CASE FILE

A Public Sponsor for a Private Namespace

An enterprise can need outside confirmation of an internal DNS arrangement without wanting to publish its internal directory. RFC 9704 offers a way to separate those disclosures. The difficult decisions concern what remains visible, how much authority one approval covers, and who…

Sep 7, 2026
AI editorial portrait of Suzanne Woolf in a DNS operations setting where one shared path separates toward multiple server instances.

IETF

Suzanne Woolf and the Server Label That Is Not a Machine Identity

A DNS reply can carry a label for the server that produced it. That sounds like identity until anycast, operator-defined bytes and hop-by-hop scope are allowed back into the picture. Suzanne Woolf’s work on the requirements behind NSID offers a more useful interpretation: the…

Sep 7, 2026
AI editorial portrait of Sara Dickinson in a DNS operations setting where an encrypted path separates into processing, storage and onward-disclosure paths.

IETF

Sara Dickinson and the Resolver Promise Encryption Cannot Prove

The padlock beside a DNS resolver name is reassuring because it proves something useful: the client has protected its conversation on the way to a particular service. It is also dangerously easy to ask that icon to prove the rest. Sara Dickinson’s co-authored RFC 8932 follows the…

Sep 7, 2026
Allison Mankin in an AI editorial portrait beside a bounded pane of observed DNS signals that branch into unresolved possible causes.

ICANN

Allison Mankin and the Name-Collision Sample That Could Not Prove Its Cause

A root server can record a query for a private-looking name with great precision. The record still cannot say which application produced it, who owns the broken dependency, how many users rely on it or what a future delegation would harm. Allison Mankin’s work on RFC 8023 helps…

Sep 7, 2026
An amber candidate key waits behind a validation gate while three evidence paths converge on a cyan trusted chamber and the incumbent key remains connected.

CASE FILE

The Key Was Known. It Was Not Yet Trusted

A self-signed DNS update arrives at a parent carrying a new key and an instruction to delete the old one. The signature proves that somebody holds the new private key. It does not prove that this somebody may change the child's delegation. As DNSOP's 7 September Last Call reaches…

Sep 7, 2026
Two nearly identical DNS paths converge on one resolver and then enter separate blue and amber application-policy chambers, showing a trust boundary displaced by an explicit terminal root-label node.

CASE FILE

The Final Dot Vanished. The Trust Boundary Moved with It

Two hostnames can lead DNS to the same node and still lead an application to different security decisions. As the DNSOP Working Group closes its 7 September Last Call on guidance for bringing domain names into applications, a recent curl flaw gives the abstract warning a concrete…

Sep 6, 2026
Conceptual illustration of QNAME minimisation as a bounded DNS query sequence across delegation and cache states.

IETF

QNAME Minimisation Is a Query-Sequence Contract, Not a Privacy Switch

A resolver may advertise QNAME minimisation while exposing very different names, costs and failure modes from one lookup to the next. The feature matters only when operators can reconstruct the bounded sequence produced by delegation knowledge, cache state and negative proofs.

Sep 4, 2026
A cyan DNS signal stops at layered verification gates between child and parent zone hierarchies.

CASE FILE

DNS Received the Hint. The Parent Still Had to Decide: RFC 9859’s Delegation Boundary

RFC 9859 can make delegation maintenance faster. It cannot make a notification into a parent-side decision, or turn a received response into proof that DNSSEC or delegation state has changed.

Sep 1, 2026