惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
宝玉的分享
宝玉的分享
Jina AI
Jina AI
IT之家
IT之家
博客园 - Franky
MyScale Blog
MyScale Blog
Y
Y Combinator Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
I
InfoQ
雷峰网
雷峰网
WordPress大学
WordPress大学
Microsoft Security Blog
Microsoft Security Blog
Google DeepMind News
Google DeepMind News
美团技术团队
S
SegmentFault 最新的问题
罗磊的独立博客
博客园 - 聂微东
大猫的无限游戏
大猫的无限游戏
H
Help Net Security
D
Docker
博客园 - 司徒正美
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
阮一峰的网络日志
阮一峰的网络日志
M
MIT News - Artificial intelligence

Infoblox Blog

You Don’t Need a Locksmith: Preparing for the Root Zone Key Signing Key (KSK) Rollover in October 2026 AI Agent Security: DNS-AID and Protective DNS | Infoblox Illegal Gambling Sites Reveal Three Types of Cybercrime Infoblox vNIOS on AWS China | Unified DDI Across Global and China Cloud Environments DNS-AID: Securing AI Agents and the Future of Agentic Commerce Modernizing Federal Networks Without Compromise | Infoblox DNS at IETF 126 To Open Weight or Not to Open Weight - That Should NOT be the question AI Governance with DNS Security | Infoblox Infoblox Supports the Next Generation of Cybersecurity Talent at Cyber Battle Australia The Second Life of Expired Domains Illegal Streaming Fronts a $7M Dropcatch Domain Operation Expired Malicious Domains Bring New Threats to Life How Many AI Agents Are Running in Your Organization? Infoblox IQ for DDI Is Now Generally Available | AI for Network Operations Kentik Joins Infoblox: Network Observability & AI Cybercrime Trends and Threat Intelligence | Infoblox AI’s First Move Is a Name Lookup External Attack Surface Management: See What Attackers See | Infoblox FedRAMP DDI Management with Infoblox Government Cloud Inside a Global Procurement-Themed AiTM Phishing Campaign The Missing Link in the Anti-Scam Chain: Why DNS Belongs in the Room. (DNS, GASA, Global Anti-Scam Alliance, DNS Threat Intelligence) Oracle Cloud Discovery for Universal Asset Insights | Infoblox Why Asset Discovery Integrations Start with Network Intelligence Infoblox Kentik Acquisition: AI-Driven Network and Security Intelligence Proxyware actor behind fake 7-Zip is bigger than you think! Using Protective DNS to Dismantle Global Scam Networks | Infosecurity Europe 2026 Residential Proxies: Why DNS Is the Stronger Play NIST Maps DNS Security to the Cybersecurity Framework 2.0 Trusted Infrastructure Data for AI and AgenticOps | Infoblox
Break out the bubbly: NIST SP 800-81r3 has been published!
Cricket Liu · 2026-03-20 · via Infoblox Blog

Back on April 10, I mentioned that the U.S. National Institute of Standards and Technology, or NIST, had released a draft of a new version of their venerable “Secure Domain Name System (DNS) Deployment Guide,” called NIST SP 800-81 for short. Well, 800-81r3 has just been published as an official set of recommendations and best practices.

As I said back in April, SP 800-81 has been a mainstay of the DNS community since its original publication back in 2006. DNS administrators have turned to it ever since for guidance on how to securely configure and manage their DNS infrastructure. But the latest update was in 2013, too far back to include important developments in the World of DNS (yes, there is such a thing) such as Protective DNS and Encrypted DNS.

I’m very proud to say that my colleague Ross Gibson and I had a hand in this new version. We approached Scott Rose, who’s written every version of SP 800-81 since the beginning, and asked if he’d be interested in an update. Scott was amenable, and together, the three of us added what I feel is important new material on when and how to deploy Protective DNS (hint: nearly always) and Encrypted DNS. We also added a great deal of specific material on the litany of threats to DNS and how to address them, covered DNS hygiene, recommended dedicated DNS servers and much more.

If you’re wondering how this NIST document might affect you, the SP 800 series provides guidance, but some documents in the series are incorporated into regulatory frameworks. For example, the European NIS2 Directive refers to NIST SP 800-81 for its best practices for secure DNS deployment.

Our hope is that this update will continue the long tradition of SP 800-81 as a critical resource for DNS administrators. To understand what SP 800‑81r3 means in practice, read the NIST DNS Security Best Practices: Top 5 Takeaways blog or download your copy today.

Footnotes

  1. If this accounting of the changes seems overly high-level, never fear: Ross is right on my heels with a blog on the details of the update.

Executive Vice President and Chief Evangelist, Infoblox

Cricket is one of the world’s leading experts on the Domain Name System (DNS) and serves as the liaison between Infoblox and the DNS community. Before joining Infoblox, he founded an internet consulting and training company, Acme Byte & Wire, after running the hp.com domain at Hewlett-Packard. Cricket is a prolific speaker and author, having written a number of books including “DNS and BIND,” one of the most widely used references in the field, now in its fifth edition.

View All Posts