Compliance table

The following table describes the (minimal) compliance of PowerDNS products with various important standards.

If you miss a standard that is important to you, please contact us.

RFC 1034

Domain names - concepts and facilities

RFC 1035

Domain names - implementation and specification

RFC 1464

Using the Domain Name System To Store Arbitrary String Attributes

RFC 1876 (Auth)

A Means for Expressing Location Information in the Domain Name System

RFC 1982 (Auth)

Serial Number Arithmetic

RFC 1995 (Downstream)

Incremental Zone Transfer in DNS

RFC 1996

A Mechanism for Prompt Notification of Zone Changes (DNS NOTIFY)

RFC 2136

Dynamic Updates in the Domain Name System (DNS UPDATE)

RFC 2181

Clarifications to the DNS Specification

RFC 2230

Key Exchange Delegation Record for the DNS

RFC 2308

Negative Caching of DNS Queries (DNS NCACHE)

RFC 2536

DSA KEYs and SIGs in the Domain Name System (DNS)

RFC 2538

Storing Certificates in the Domain Name System (DNS)

RFC 2539

Storage of Diffie-Hellman Keys in the Domain Name System (DNS)

RFC 2671

Extension Mechanisms for DNS (EDNS0)

RFC 2782

A DNS RR for specifying the location of services (DNS SRV)

RFC 2845

Secret Key Transaction Authentication for DNS (TSIG)

RFC 2930

Secret Key Establishment for DNS (TKEY RR)

RFC 3007

Secure Domain Name System (DNS) Dynamic Update (TSIG only)

RFC 3225

Indicating Resolver Support of DNSSEC

RFC 3263

Session Initiation Protocol (SIP): Locating SIP Servers

RFC 3401

Dynamic Delegation Discovery System (DDDS) - Part One: The Comprehensive DDDS

RFC 3402

Dynamic Delegation Discovery System (DDDS) - Part Two: The Algorithm

RFC 3403

Dynamic Delegation Discovery System (DDDS) - Part Three: The Domain Name System (DNS) Database

RFC 3404

Dynamic Delegation Discovery System (DDDS) - Part Four: The Uniform Resource Identifiers (URI) Resolution Application

RFC 3596

DNS Extensions to Support IP Version 6

RFC 3597

Handling of Unknown DNS Resource Record (RR) Types

RFC 3658

Delegation Signer (DS) Resource Record (RR)

RFC 4025

A Method for Storing IPsec Keying Material in DNS

RFC 4033

DNS Security Introduction and Requirements

RFC 4034

Resource Records for the DNS Security Extensions

RFC 4035

Protocol Modifications for the DNS Security Extensions

RFC 4255

Using DNS to Securely Publish Secure Shell (SSH) Key Fingerprints

RFC 4343

Domain Name System (DNS) Case Insensitivity Clarification

RFC 4398

Storing Certificates in the Domain Name System (DNS)

RFC 4509

Use of SHA-256 in DNSSEC Delegation Signer (DS) Resource Records (RRs)

RFC 4592

The Role of Wildcards in the Domain Name System

RFC 4694

Number Portability Parameters for the "tel" URI

RFC 4701

A DNS Resource Record (RR) for Encoding Dynamic Host Configuration Protocol (DHCP) Information (DHCID RR)

RFC 4892

Requirements for a Mechanism Identifying a Name Server Instance

RFC 5001

DNS Name Server Identifier (NSID) Option

RFC 5155

DNS Security (DNSSEC) Hashed Authenticated Denial of Existence

RFC 5452

Measures for Making DNS More Resilient against Forged Answers

RFC 5702

Use of SHA-2 Algorithms with RSA in DNSKEY and RRSIG Resource Records for DNSSEC

RFC 5933

Use of GOST Signature Algorithms in DNSKEY and RRSIG Resource Records for DNSSEC

RFC 6147

DNS64: DNS Extensions for Network Address Translation from IPv6 Clients to IPv4 Servers

RFC 6594

Use of the SHA-256 Algorithm with RSA, Digital Signature Algorithm (DSA), and Elliptic Curve DSA (ECDSA) in SSHFP Resource Records

RFC 6605

Elliptic Curve Digital Signature Algorithm (DSA) for DNSSEC

RFC 6672

DNAME Redirection in the DNS

RFC 6698

The DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS) Protocol: TLSA

RFC 6840

Clarifications and Implementation Notes for DNS Security (DNSSEC)

RFC 6891

Extension Mechanisms for DNS (EDNS(0))

RFC 7218

Adding Acronyms to Simplify Conversations about DNS-Based Authentication of Named Entities (DANE)

RFC 7344 (publication)

Automating DNSSEC Delegation Trust Maintenance

RFC 7479

Using Ed25519 in SSHFP Resource Records

RFC 7646

Definition and Use of DNSSEC Negative Trust Anchors

RFC 7671

The DNS-Based Authentication of Named Entities (DANE) Protocol: Updates and Operational Guidance

RFC 7871

Client Subnet in DNS Queries

RFC 7984

Locating Session Initiation Protocol (SIP) Servers in a Dual-Stack IP Network

RFC 8020

NXDOMAIN: There Really Is Nothing Underneath

RFC 8078 (publication)

Managing DS Records from the Parent via CDS/CDNSKEY

RFC 8080

Edwards-Curve Digital Security Algorithm (EdDSA) for DNSSEC

RFC 8198

Aggressive Use of DNSSEC-Validated Cache

RFC 8484

DNS Queries over HTTPS (DoH)

RFC 8624

Algorithm Implementation Requirements and Usage Guidance for DNSSEC

RFC 8914

Extended DNS Errors

RFC 8945

Secret Key Transaction Authentication for DNS (TSIG)

RFC 9432

DNS Catalog Zones