DNSSEC signs answers but does not hide them
DNSSEC lets you verify that a DNS answer really came from whoever controls the domain and has not been tampered with.
It is a signature, not an envelope. Everything is still visible to anybody watching, including which sites you are looking up. People frequently expect it to provide privacy and it provides authenticity, which is a different property and the one that stops an attacker forging answers.
More on DNS and domains
- DNS is a directory, not proof of safetyIt only answers where
- Encrypted DNS protects the resolver path, not the destinationCovered to the desk, open to the door
- Registrar compromise can outrank server securityIt all hangs from one fitting
- Registrar locks add friction to domain theftThe pin that makes them stop
- Dangling DNS can point to somebody else's resourceYour plate, their locker
- Subdomain takeover begins with abandoned ownershipNobody minding the stall
