Topic
DNS Delegation Power
Within the Topic facet, DNS Delegation Power topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

IETF
David Lawrence and the DNS Answer That Outlived Its TTL
When a DNS answer reaches the end of its TTL, a recursive resolver normally discards or refreshes it. RFC 8767 allows a narrower choice during failure: preserve the expired copy for a bounded time, return it only after a real refresh attempt cannot produce usable data, and keep…

IETF
Steve Sheng and the Lock That Did Not Stop DNSSEC Maintenance
A domain can display an update lock while its DNSSEC delegation data still changes legitimately. RFC 10026 resolves the apparent contradiction by asking what the lock actually binds: which actor set it, whose command it rejects, and which independently authenticated maintenance…

IETF
Peter Thomassen and the Update That Needed Every Authoritative Server
A child zone can publish a perfectly signed request for its parent to change trust or delegation data. RFC 9975 asks a harder question before the parent acts: did the request come from the delegated authoritative service as a whole, or only from the one server that happened to…
CASE FILE
The DNS Said the Domain Was for Sale. It Did Not Have Authority to Close the Deal
RFC 10023 makes a registered domain’s availability visible in DNS. Its compact signal can open a negotiation while the domain remains in use; it cannot identify the rightful seller, bind a price or complete the transfer.
CASE FILE
The Zone Was Online. One Address Family Could Not Reach Its Authority: RFC 10001 and DNS Partition
The dashboard stayed green because its resolver quietly used IPv4. An IPv6-only resolver followed the same published delegation, reached a missing dependency and stopped. The name had not disappeared; its authority existed on one transport path and not the other. RFC 10001 turns…
CASE FILE
The Packet Came Back Complete. The Evidence Set Didn't: RFC 10029 and Authority Across DNS Types
A resolver asks once for an address, an IPv6 address and an HTTPS service binding. One successful packet returns. That packet can still leave one of the three questions unfinished. RFC 10029 makes the missing distinction operational: a shared envelope can reduce transactions, but…
CASE FILE
The Registry Published the TTL. The Resolver Kept Its Own Clock: RFC 10037 and the Authority to Describe a DNS Change Window
A registry can now place a delegation TTL in an RDAP response, where an operator can read it without querying the DNS. The number is useful precisely because its authority is narrow. It describes what the registry database has provisioned; it does not reveal how many seconds…
CASE FILE
The Error Returned as a New Question: DNS Report-Channel and the Authority of Feedback
An authoritative server can announce where it wants to hear about failures it cannot see. It cannot make a resolver diagnose, report or believe anything. DNS Error Reporting turns one local validation failure into a second DNS query, then leaves transport, caching and human…
CASE FILE
The Packet Hid Its Exact Length. The Pattern Still Spoke: EDNS Padding and the Limits of DNS Privacy
An encrypted DNS message can conceal its names and answers while leaving a surprisingly useful silhouette. EDNS Padding changes that silhouette by adding bytes. The difficult question is not whether the packet became larger, but whether client, server, transport and path made…
CASE FILE
The Record Bound the Options. The Client Still Chose the Connection: DNS SVCB, HTTPS and Service Authority
A domain owner can authenticate a list of preferred endpoints, protocols and connection parameters before the first application exchange. That does not make the first preference a command, turn a routing target into the origin, or prove which path a real client can securely…
CASE FILE
The Feed Was Valid. The Answer Was Local: DNS Response Policy Zones and the Authority to Rewrite Resolution
An authenticated threat feed can tell a resolver what a publisher recommends. It cannot decide which users lose a name, whether the answer should disappear or be replaced, or who owns the damage when a correct transfer produces the wrong operational result.
CASE FILE
The Digest Matched. The Zone Was Still Wrong: ZONEMD and the Limits of Cryptographic Integrity
A whole-zone checksum can expose truncation, corruption and substitution. It can also authenticate a mistake with perfect precision. The decision for infrastructure leaders is not whether to trust cryptography, but how narrowly to interpret what it has proved.
CASE FILE
The Signal Was Signed. The Delegation Was Not Yet Secure: CDS/CDNSKEY and the Authority to Publish DS
A child zone can publish a perfectly signed request for a new DNSSEC secure entry point and still lack the one chain that would validate it. CDS/CDNSKEY makes parent coordination machine-readable; it does not collapse operational control, registrant authority, parent admission…
CASE FILE
The Catalog Was Valid. The Deletion Was Not: DNS Catalog Zones and the Authority to Provision
An authenticated DNS transfer can deliver a perfectly formed catalog whose operational consequence is to remove every zone from a secondary fleet. The transport may be trustworthy and the syntax impeccable while the decision encoded inside it is still wrong. DNS Catalog Zones…
Europe and Middle East Cloud Services Trends
The regional boundary behind Genesis Cloud’s GPU capacity
Genesis Cloud’s accelerator inventory becomes useful capacity only when networking, data placement, images, security controls and recovery procedures can support the intended workload. Its documented regional boundaries therefore turn a catalogue question into an architectural…

History
A Detour Could Not Also Be a Destination: The Design of DNS CNAME
DNS could let an old name lead to a new destination, but only by making the old node surrender every ordinary answer of its own. CNAME turned that apparent limitation into a reliable instruction: cache the detour, restart the question, and keep authority over the alias separate…
CASE FILE
The Answer Had Expired. The Failure Had Not: DNS Serve-Stale and the Authority Beyond TTL
A DNS answer can outlive its ordinary freshness without becoming current again. Serve-stale is the resolver's narrow authority to prefer a known old answer over a fresh failure, but only after the source has been consulted, the failure has been bounded and the age of the…

IETF
Joe Abley and the Trust Anchor That Had to Declare Where Trust Began
DNSSEC can prove a chain only after a resolver has decided where the chain starts. Joe Abley's work on the root trust-anchor publication format makes that first decision unusually legible: a signed file can prove where data came from, but it cannot order an operator to believe…

Story
K-root Says It Meets Every Expectation. The Evidence Is Uneven
RIPE NCC has answered the root-server community's operating expectations one by one. That makes K-root easier to question than a service hidden behind a general assurance of competence. Yet RIPE-859 also reveals a governance gap: a public metric, a control description and the…

IETF
Ray Bellis and the DNS Connection That Became a Session
A TCP socket can remain open without anyone agreeing what state it carries. RFC 8490 made that distinction explicit for DNS: the connection is transport; the session is a mutually recognized set of rights, timers and obligations. Ray Bellis and his co-authors turned persistence…
