[DNSOP] DNS Security TXT - A standard for nominating security contact points and policies via DNS TXT records
Stephane Bortzmeyer <bortzmeyer@nic.fr> Thu, 06 August 2026 15:58 UTC
Return-Path: <bortzmeyer@nic.fr>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id F0C1C124D4AA9 for <dnsop@mail2.ietf.org>; Thu, 6 Aug 2026 08:58:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786031883; bh=8sTHZ7uvxvkayGWPm6mzELnaLETFJw7m6mbSapgasXg=; h=Date:From:To:Subject; b=aiJrdtWafV7iCHA0SdsPjPWknLu1AboYdMhJtOX2ufSqMDH6PGHokD8gGhXp6/D54 Mtc/5xwwogODiqwcbDIwlzy7Ba15ocMzyocM5zsqXQE33VFGQeyZGdDOrexJ/oxZlt nDaw0lNuFqKVzugB0C3qL6qVNVbbmDIeyMV0cstQ=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=nic.fr
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id eBVocv5uUQQA for <dnsop@mail2.ietf.org>; Thu, 6 Aug 2026 08:58:03 -0700 (PDT)
Received: from mx2.nic.fr (mx2.nic.fr [IPv6:2001:67c:2219:10::51:2]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 60D96124D4AA0 for <dnsop@ietf.org>; Thu, 6 Aug 2026 08:58:03 -0700 (PDT)
Received: from pps.filterd (mx2.nic.fr [127.0.0.1]) by mx2.nic.fr (8.18.1.11/8.18.1.11) with ESMTP id 676FhKcN1947813 for <dnsop@ietf.org>; Thu, 6 Aug 2026 15:57:55 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nic.fr; h= content-type:date:from:message-id:mime-version:subject:to; s= nic-20240601; bh=8sTHZ7uvxvkayGWPm6mzELnaLETFJw7m6mbSapgasXg=; b= aZxHvAlZ6cr5OaAHeLATyBpMJ9YiugfT50grS8vEsWhc2TWgOe+PVNQCbnyNkH0w Kn1mveIHII+hxaPUDTXOBGt98OFhTTOtcx17DdGpOWkO4gW1ELspy7IkAgOPoq2l UYFmngMWhglboteiGZbI3jDUR9vIWraiiBnG+CZjlk4KMJTxNXLihoihB1JjfABJ R87VNggiUqbJmRS7L4qLOfMS5cZtIpqzQAoV19F5AKFMcAYNjmDHAtbg2DnOXnjy awmmSv76M8X15RaT4mmya+zwtmu1S2f72GPMjd/5qfVCHEEV80rRNwWWylxnxIUb qw6IW9DiWupZVm63YOa22w==
Received: from relay01.prive.nic.fr (relay01.prive.nic.fr [10.1.50.11]) by mx2.nic.fr (PPS) with ESMTP id 4fvq43022s-1 for <dnsop@ietf.org>; Thu, 06 Aug 2026 15:57:55 +0000 (GMT)
Received: from b12.nic.fr (b12.users.prive.nic.fr [10.10.23.33]) by relay01.prive.nic.fr (Postfix) with ESMTP id 4D165608468A for <dnsop@ietf.org>; Thu, 6 Aug 2026 17:57:55 +0200 (CEST)
Received: by b12.nic.fr (Postfix, from userid 1000) id 79B9E3FBEF; Thu, 06 Aug 2026 17:57:54 +0200 (CEST)
Date: Thu, 06 Aug 2026 17:57:54 +0200
From: Stephane Bortzmeyer <bortzmeyer@nic.fr>
To: dnsop@ietf.org
Message-ID: <anSvAliTcPxQqcuX@nic.fr>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
X-Operating-System: Debian GNU/Linux 13.6
X-Kernel: Linux 6.12.96+deb13-amd64 x86_64
X-Charlie: Je suis Charlie
Organization: NIC France
X-URL: http://www.nic.fr/
X-Proofpoint-GUID: Lclfzsk7j6BuHvjnMWK1B2bWpvEhZ2zn
X-Proofpoint-Spam-Info: AW1haW4tMjYwODA2MDEyNCBTYWx0ZWRfX3XvjdRmBoPD/ ADiNI4gI6fVUl9Y/LOZcu+Y4uDoowGA8dcP7KvGvXIddwSMZv/pbGSWCHKY5CEI9qyx4VcCBqcl wQ2+2qEpKvQnu+uetze+YcbLOnBq+vs=
X-Proofpoint-ORIG-GUID: Lclfzsk7j6BuHvjnMWK1B2bWpvEhZ2zn
X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODA2MDEyNCBTYWx0ZWRfX/1SE7BBShgVJ 65HjWgu50/2oXQdvOoruAs6IkK1NLpyOEtIW6fQ9qUa2PytQU3uLA/zAbu7ap5azO75L8dHZobE udzKhC5XSRA4IwRW2qt/1G/lkEXs7n/whH2+tEwuIR646WJKxlbcEJvyh22CgFm5vCgpZqtrDcG W2OJyaejn7C7IzjygNeInJSIHGC0wieAgMqZHK5IQZ0XySoin9h3Dl73yXf/EWrcQw78/xaiprq vDCMi+5q9ylvetc2OFZ8qbKQMhAsLejzFeF0V5FVm3gNrgFqD5oSx2KyrPWSI5+ZATZcd0+kYW1 mGOYGeeAqskZdxx+LD3Wfdk3L3Ewp7ai0dPXSBodhrH5oB/tCmK6c/EskJf/ykEItCWyfGGOOgx 8knz4Obz
Message-ID-Hash: AMKG7FK4N6X2R7OHW5XMWJJL3HDFUOCY
X-Message-ID-Hash: AMKG7FK4N6X2R7OHW5XMWJJL3HDFUOCY
X-MailFrom: bortzmeyer@nic.fr
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] DNS Security TXT - A standard for nominating security contact points and policies via DNS TXT records
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/BeL8TrjG7cLoF-Cx7uZspEsQevA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
It does not seem there is an Internet-Draft for this but it may interest people here: Summary: The report channel, published in DNS When people find security issues in Internet-facing systems, the correct channel to report them isn't always clear, and the relevant disclosure policy for the system isn't always apparent. DNS Security TXT extends the work done by security.txt to answer this question using DNS, arguably the most ubiquitous system on the Internet. When deployed, it gives security researchers, Internauts, and concerned Internet citizens clear and authoritative direction to the correct channels for reporting security issues, and to the policies an organization sets out for all systems under a domain. https://dnssecuritytxt.org/
- [DNSOP] DNS Security TXT - A standard for nominat… Stephane Bortzmeyer
- [DNSOP] Re: DNS Security TXT - A standard for nom… Paul Wouters