HomeSecurityNIST updates DNS security guidance after 12 years

NIST updates the DNS security guidance after 12 years

The latest update to DNS security guidance from the National Institute of Standards and Technology (NIST) marks a new era in how organizations are expected to secure one of the internet’s most critical systems. Published as NIST SP 800-81r3, this revision replaces the previous 2013 edition, closing a gap of more than a dozen years without significant federal updates in this area.

See also: AWS Bedrock's 'isolated' sandbox comes with a DNS egress

NIST

The DNS, or Domain Name System, plays a fundamental role in almost every network connection. Despite this, DNS security practices have historically lagged behind other parts of enterprise infrastructure. With SP 800-81r3, NIST brings modern threats, technologies, and operational realities to the forefront, providing updated DNS security guidance for both leadership and technical teams.

A Modern Approach to DNS Security Guidance. The revised NIST SP 800-81r3 document is structured around three core pillars: the use of DNS as a preventive security measure, strengthening the DNS protocol itself, and securing the infrastructure that supports DNS services. Importantly, the guidance is tailored for two audiences: executives who make strategic cyber‑security decisions and operational teams responsible for implementation and maintenance.

One of the most notable changes in this DNS security guidance is the emphasis on DNS as more than a lookup service. Instead, it is positioned as an active enforcement layer capable of detecting and mitigating threats in real time.

A key reference point of SP 800-81r3 is the focus on the “protective DNS”. This concept refers to DNS services enhanced with security capabilities that can inspect queries and responses, block malicious domains, filter content categories, and generate log files for analysis and incident response.

The NIST recommends a hybrid approach where possible, noting that the combination of cloud services with on-premises backup solutions ensures resilience even during outages. The DNS security guidance also emphasizes the integration of DNS log files with SIEM platforms and their correlation with DHCP lease data to map activity to specific devices during investigations.

Another important area covered in NIST SP 800-81r3 is encrypted DNS. The document discusses three core protocols:

  • DNS over TLS (DoT) on port TCP 853
  • DNS over HTTPS (DoH) on port TCP/UDP 443
  • DNS over QUIC (DoQ) on port UDP 853

These protocols encrypt communication between clients and DNS resolvers, improving privacy and integrity. However, they also shift the security burden. NIST requires encrypted DNS for U.S. federal policy services where technically feasible. At the same time, DNS security guidance warns that organizations must carefully configure browsers and applications to ensure they do not bypass internal DNS controls.

See also: Evasive Panda: AitM attacks and DNS poisoning to distribute malware

NIST updates the DNS security guidance after 12 years
To maintain control, the guidance recommends:
  • Blocking unauthorized DoT traffic via TCP port 853
  • Restricting DoH using firewall rules and RPZs
  • Using mobile device management tools to enforce DNS settings

The SP 800-81r3 update also modernizes DNSSEC recommendations. It aligns supported algorithms with RFC 8624 and NIST SP 800-57, including:

  • RSA with SHA-256
  • ECDSA P-256 and P-384
  • Ed25519 and Ed448

The guidance prefers the ECDSA and Edwards-curve algorithms due to their smaller key sizes, which help maintain DNS response efficiency and avoid fallback to TCP.

Key management is also a focus point. DΝSSEC signing keys should have a lifetime of one to three years, while RRSIG validity should remain short, about five to seven days, to limit exposure if a key is compromised. Hardware security modules are recommended for protecting private keys.

Other recommendations include:
  • Deploy at least two authorized servers on separate networks
  • Distribute servers geographically across multiple locations
  • Use of a hidden primary server to reduce exposure to attacks

Dedicated infrastructure for DNS is preferred to minimize the attack surface and ensure sufficient resources for logging and security capabilities. Where full segregation is not feasible, the combined use of DNS with tightly coupled services such as DHCP is considered acceptable.

See also: Detour Dog malware distributes Strela Stealer via DNS TXT Records

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

DNS attacks

Overall, this updated DNS security guidance from NIST represents an extensive modernization of the way organizations should approach DNS. With SP 800-81r3, DNS is no longer treated as a passive service but as a central pillar of enterprise cyber‑security strategy.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS