ARIN Deploys DNSSEC Zone Signing

Posted: 01 July 2009

On 1 July 2009 ARIN will begin phase two of its DNSSEC project by publishing the zones that it is authoritative for under

Because the parent zone ( is not signed, you will need to place the advertised keys as part of your DNS server configuration as defined on ARIN's trust anchor list. The list is available for download in BIND-style and zone-file format at:

The DNSSEC project will be completed in three phases. The third and final phase is allowing DS records from ARIN-issued delegations that have secured zones. View the detailed deployment plan at:

To learn more about DNSSEC, please look at


Mark Kosters
Chief Technology Officer
American Registry for Internet Numbers (ARIN)