ActorStack.dev

DNSSEC adoption is 5.0%, and that number means nothing without its TLD

Measured across the whole zone, 5.0% of domains publish a DS record. Per registry the rate runs from 0% to 100%, which is what makes the global figure unusable on its own.

By Oswaldo Carabano5 min read

Short answer

Across every domain in the covered zone files, 5.0% publish a DNSSEC delegation-signer record. That global figure is close to useless applied to any individual domain, because the rate ranges from 0% to 100% depending on the registry: 14.1% in `.dev`, 5.5% in `.net` and 0.9% in `.bond`. A domain without DNSSEC in a TLD where almost nobody publishes it is unremarkable, and one without it in a TLD where most do is worth a question. Publishing the per-TLD rates alongside the global one is what stops a security report reading 5% as a weakness of the domains rather than as the current state of the registries they sit in.

Key points

  • Across every domain in the covered zones, 5.0% publish a DNSSEC delegation-signer record.
  • Per registry the rate runs from 0% to 100%, which makes the global figure close to useless applied to an individual domain.
  • Measured rates include 14.1% in `.dev`, 5.5% in `.net` and 0.9% in `.bond`, a spread of more than an order of magnitude.
  • A domain without DNSSEC in a TLD where almost nobody publishes it is unremarkable, and the same absence elsewhere is a finding.
  • The delegation-signer record is in the zone because it is part of the delegation, which is why adoption is measurable from registry data at all.
  • Publishing the denominator next to the rate is what stops a report treating a registry's state as a property of the domains in it.
On this page5 sections

A single global percentage is one of the easiest ways to publish a true number that produces a false conclusion.

The global rate, and its limits

Across every domain in the covered zone files, 5.0% publish a DNSSEC delegation-signer record. As a description of the namespace that is accurate. As a benchmark for any individual domain it is close to useless.

The spread between registries

TLDDomains publishing a DS record
.dev14.1%
.net5.5%
.bond0.9%
All covered gTLDs5.0%

Across the full set the range runs from 0% to 100%, depending entirely on whether that registry's registrars sign by default, offer it as an option, or barely support it.

Why DNSSEC is visible in a zone file at all

Because the delegation-signer record is part of the delegation. It is what the parent zone publishes to vouch for the child's signing key, so it sits alongside the NS records rather than down at the domain's own nameservers — which makes DNSSEC one of the very few security properties measurable straight from registry data.

Reading a domain's DNSSEC state honestly

An unsigned domain in .bond, where 0.9% of domains are signed, tells you nothing about its operator. An unsigned domain in a registry where most are signed is worth a question. The same boolean, two completely different findings, and only the denominator separates them.

Reporting a rate with its denominator

Publish the per-TLD rate next to the global one, always. Without it a security report reads “5% DNSSEC” as a weakness of the domains examined rather than as the current state of the registries they happen to sit in — the same failure mode as treating a DNS provider as a technology stack, and it shows up wherever a rate travels without its base. It is also why the reverse lookup publishes its concentration figures.

Frequently asked questions

What percentage of domains use DNSSEC?
Across the covered zone files, 5.0% of domains publish a delegation-signer record. The figure varies enormously by registry, so it describes the namespace as a whole rather than any particular TLD within it.
Why does DNSSEC adoption vary so much by TLD?
Because registries and their registrars differ in whether signing is default, easy or even offered. Measured rates run from 0% to 100%, including 14.1% in `.dev`, 5.5% in `.net` and 0.9% in `.bond`.
Is a domain without DNSSEC a security problem?
It depends entirely on its TLD. In a registry where almost nobody publishes a DS record, the absence is unremarkable and says nothing about the operator. In one where most domains are signed, the same absence is worth asking about.
Why can a zone file show DNSSEC at all?
Because the delegation-signer record is part of the delegation itself: it is what the parent zone publishes to vouch for the child's signing key. That makes DNSSEC one of the few security properties measurable straight from registry data.

Sources

Every URL below was requested and returned a page on the date shown.

  1. Platform docschecked 18 Sept 2026
    RFC 4034 — Resource Records for the DNS Security ExtensionsIETF
  2. Operator claimchecked 18 Sept 2026
    Reverse Nameserver Lookup — Actor README and input schemaActorStack / Apify Store
  3. Law or regulatorchecked 18 Sept 2026
    Root Zone Database — the delegation record for every TLDIANA
Racks of network equipment in a dimly lit server room, lit blue by their indicators.
DomainsGuide

Reverse nameserver lookup

Pivoting from a nameserver to the domains delegated to it is useful on infrastructure that belongs to one organisation and useless on a large provider's. The difference is the whole technique.

6 min
A row of residential mailboxes on posts in front of a wooden fence and trees.
DomainsGuide

Detecting domain hijacking

Whoever controls the nameservers controls the mail, the site and the certificates. That change happens in the registry zone, which is the one layer most monitoring never looks at.

7 min
Racks of network equipment in a dimly lit server room, lit blue by their indicators.
DomainsMeasured

What dns_provider can tell you

The nameserver identifies who runs the DNS for 69.1% of domains. It does not identify what a site is built with, and the measurement that settled that question is worth seeing.

5 min