Detailed Monitoring Summary:

DNSSEC Summary
2,688,897 Zones
2,124,112 DNSSEC enabled zones
2,031,512 Zones use both KSKs and ZSKs
182 Zones are serving revoked keys
1,829,476 DNSSEC verified zones
2,072,588 Production DNSSEC-enabled zones
Distribution of key algorithms in use:
Algorithm # Keys
Unknown Algorithm28
DSA-NSEC3-SHA1 [DSA-NSEC3-SHA1]17
DSA/SHA-1 [DSA]220
ECC/GOST [ECC-GOST]115
ECDSA Curve P-256 with SHA-256 [ECDSAP256SHA256]543,339
ECDSA Curve P-384 with SHA-384 [ECDSAP384SHA384]13,076
Private [PRIVATEOID]5
RSA-NSEC3-SHA1 [RSASHA1-NSEC3-SHA1]1,643,466
RSA/MD5 [RSAMD5]22
RSA/SHA-1 [RSASHA1]61,862
RSA/SHA256 [RSASHA256]3,018,737
RSA/SHA512 [RSASHA512]8,658
DANE Summary
48,412 DANE enabled zones with TLSA records
234 PKIX based Trust Anchor TLSA records (Cert Usage 0)
2,277 PKIX based End Entity TLSA records (Cert Usage 1)
2,248 DANE based Trust Anchor TLSA records (Cert Usage 2)
34,009 DANE based End Entity TLSA records (Cert Usage 3)
1,459 Zones have deployed TLSA for Secure SMTP (Port 465)
658 Zones have deployed TLSA for Secure POP3 (Port 995)
1,960 Zones have deployed TLSA for SMTP with STARTTLS (Port 587)
176 Zones have deployed TLSA for Alternate SMTP (Port 2525)
23,466 Zones have deployed TLSA for HTTPS (Port 443)
8,292 Zones have deployed TLSA for SMTP (Port 25)
442 Zones have deployed TLSA for POP3 (Port 110)
1,459 Zones have deployed TLSA for Secure IMAP (Port 993)
856 Zones have deployed TLSA for IMAP (Port 143)

Distribution of RRSIG lifetimes on DNSKEY RRsets