DNSSEC adoption is 5.0%, and that number means nothing without its TLD
Measured across the whole zone, 5.0% of domains publish a DS record. Per registry the rate runs from 0% to 100%, which is what makes the global figure unusable on its own.
Across every domain in the covered zone files, 5.0% publish a DNSSEC delegation-signer record. That global figure is close to useless applied to any individual domain, because the rate ranges from 0% to 100% depending on the registry: 14.1% in `.dev`, 5.5% in `.net` and 0.9% in `.bond`. A domain without DNSSEC in a TLD where almost nobody publishes it is unremarkable, and one without it in a TLD where most do is worth a question. Publishing the per-TLD rates alongside the global one is what stops a security report reading 5% as a weakness of the domains rather than as the current state of the registries they sit in.
Key points
Across every domain in the covered zones, 5.0% publish a DNSSEC delegation-signer record.
Per registry the rate runs from 0% to 100%, which makes the global figure close to useless applied to an individual domain.
Measured rates include 14.1% in `.dev`, 5.5% in `.net` and 0.9% in `.bond`, a spread of more than an order of magnitude.
A domain without DNSSEC in a TLD where almost nobody publishes it is unremarkable, and the same absence elsewhere is a finding.
The delegation-signer record is in the zone because it is part of the delegation, which is why adoption is measurable from registry data at all.
Publishing the denominator next to the rate is what stops a report treating a registry's state as a property of the domains in it.
A single global percentage is one of the easiest ways to publish a true number that produces a false conclusion.
The global rate, and its limits
Across every domain in the covered zone files, 5.0% publish a DNSSEC delegation-signer record. As a description of the namespace that is accurate. As a benchmark for any individual domain it is close to useless.
The spread between registries
TLD
Domains publishing a DS record
TLD.dev
Rate14.1%
TLD.net
Rate5.5%
TLD.bond
Rate0.9%
TLDAll covered gTLDs
Rate5.0%
Across the full set the range runs from 0% to 100%, depending entirely on whether that registry's registrars sign by default, offer it as an option, or barely support it.
Why DNSSEC is visible in a zone file at all
Because the delegation-signer record is part of the delegation. It is what the parent zone publishes to vouch for the child's signing key, so it sits alongside the NS records rather than down at the domain's own nameservers — which makes DNSSEC one of the very few security properties measurable straight from registry data.
Reading a domain's DNSSEC state honestly
An unsigned domain in .bond, where 0.9% of domains are signed, tells you nothing about its operator. An unsigned domain in a registry where most are signed is worth a question. The same boolean, two completely different findings, and only the denominator separates them.
Reporting a rate with its denominator
Publish the per-TLD rate next to the global one, always. Without it a security report reads “5% DNSSEC” as a weakness of the domains examined rather than as the current state of the registries they happen to sit in — the same failure mode as treating a DNS provider as a technology stack, and it shows up wherever a rate travels without its base. It is also why the reverse lookup publishes its concentration figures.
Frequently asked questions
▸What percentage of domains use DNSSEC?
Across the covered zone files, 5.0% of domains publish a delegation-signer record. The figure varies enormously by registry, so it describes the namespace as a whole rather than any particular TLD within it.
▸Why does DNSSEC adoption vary so much by TLD?
Because registries and their registrars differ in whether signing is default, easy or even offered. Measured rates run from 0% to 100%, including 14.1% in `.dev`, 5.5% in `.net` and 0.9% in `.bond`.
▸Is a domain without DNSSEC a security problem?
It depends entirely on its TLD. In a registry where almost nobody publishes a DS record, the absence is unremarkable and says nothing about the operator. In one where most domains are signed, the same absence is worth asking about.
▸Why can a zone file show DNSSEC at all?
Because the delegation-signer record is part of the delegation itself: it is what the parent zone publishes to vouch for the child's signing key. That makes DNSSEC one of the few security properties measurable straight from registry data.
Sources
Every URL below was requested and returned a page on the date shown.
Pivoting from a nameserver to the domains delegated to it is useful on infrastructure that belongs to one organisation and useless on a large provider's. The difference is the whole technique.
Whoever controls the nameservers controls the mail, the site and the certificates. That change happens in the registry zone, which is the one layer most monitoring never looks at.
The nameserver identifies who runs the DNS for 69.1% of domains. It does not identify what a site is built with, and the measurement that settled that question is worth seeing.