DNSSEC Summary
11,151,799 |
Zones |
8,824,918 |
DNSSEC enabled zones |
|
7,706,061 |
Zones use both KSKs and ZSKs |
85 |
Zones are serving revoked keys |
|
5,224,443 |
DNSSEC verified zones |
7,433,297 |
Production DNSSEC-enabled zones |
|
|
Distribution of key algorithms in use:
Algorithm
|
# Keys
|
ECDSA Curve P-256 with SHA-256 [ECDSAP256SHA256] | 5,836,718
|
ECDSA Curve P-384 with SHA-384 [ECDSAP384SHA384] | 99,157
|
Diffie-Hellman [DH] | 5
|
DSA-NSEC3-SHA1 [DSA-NSEC3-SHA1] | 6
|
RSA/SHA256 [RSASHA256] | 10,527,563
|
RSA/SHA512 [RSASHA512] | 176,374
|
RSA-NSEC3-SHA1 [RSASHA1-NSEC3-SHA1] | 60,684
|
Private [PRIVATEOID] | 1
|
RSA/MD5 [RSAMD5] | 4
|
ECC/GOST [ECC-GOST] | 4
|
DSA/SHA-1 [DSA] | 21
|
Unknown Algorithm | 211,017
|
RSA/SHA-1 [RSASHA1] | 14,049
|
|
|
DANE Summary
|
734,163
|
DANE enabled zones with TLSA records
|
|
589
|
PKIX based Trust Anchor TLSA records (Cert Usage 0)
|
|
2,054
|
PKIX based End Entity TLSA records (Cert Usage 1)
|
|
11,474
|
DANE based Trust Anchor TLSA records (Cert Usage 2)
|
|
319,955
|
DANE based End Entity TLSA records (Cert Usage 3)
|
|
|
2,079
|
Zones have deployed TLSA for POP3 (Port 110)
|
|
3,568
|
Zones have deployed TLSA for Secure IMAP (Port 993)
|
|
111,455
|
Zones have deployed TLSA for SMTP (Port 25)
|
|
4,859
|
Zones have deployed TLSA for SMTP with STARTTLS (Port 587)
|
|
1,772
|
Zones have deployed TLSA for IMAP (Port 143)
|
|
454
|
Zones have deployed TLSA for Alternate SMTP (Port 2525)
|
|
2,683
|
Zones have deployed TLSA for Secure POP3 (Port 995)
|
|
203,263
|
Zones have deployed TLSA for HTTPS (Port 443)
|
|
3,945
|
Zones have deployed TLSA for Secure SMTP (Port 465)
|
|