TRANSPARENCY & VALIDATION ARCHITECTURE

DNSSEC Methodology & Verification Model.

Detailed technical documentation on our authoritative query engine, cryptographic chain verification rules, status-first overrides, and scoring algorithm.

1

Authoritative Live Resolution Engine

Unlike passive scanners that rely on recursive resolver caches, the Uganda DNS Observatory measurement engine performs direct, iterative cryptographic lookups starting from the ICANN Root Zone (.), down to Uganda's Country Code Top-Level Domain (.ug), and finally to the target domain's authoritative nameservers.

> Inspection Pipeline Steps:
1. Query Parent TLD Nameservers for DS (Delegation Signer) records matching child target.
2. Query Child Authoritative Nameservers for DNSKEY records at zone apex.
3. Calculate cryptographic SHA digests over published KSK/ZSK keys to verify against Parent DS hash.
4. Inspect RRSIG signature records on Apex RRsets, checking inception and expiration timestamps.
5. Verify complete trust chain unbroken from ICANN Root Trust Anchor (Key Tag 20326).
2

Status-First Classification Overrides

To prevent false sense of security, our classification engine follows a strict Status-First Rule. If a domain suffers from a critical cryptographic failure (such as an expired RRSIG or a DS/DNSKEY mismatch), its classification is immediately locked to Bogus or Incomplete regardless of numerical points scored in other pillars.

Secure (100 pts)

Domain resolves, publishes valid DNSKEY records, has matching DS records at parent (.UG registry), active non-expired RRSIG signatures, and unbroken chain of trust from root.

Bogus (10 - 45 pts)

Critical validation failure! Domain publishes DNSSEC records, but cryptographic verification fails due to DS/DNSKEY hash mismatch, expired RRSIGs, or broken trust chain. Resolvers will drop queries to this domain.

Unsigned (20 pts)

Domain resolves correctly, but publishes neither DS records at the parent nor DNSKEY records at apex. No DNSSEC protection is deployed.

Incomplete (30 - 60 pts)

Partial deployment detected. For example, DNSKEY published at apex but no DS record uploaded to .UG registry, or DS present at parent but DNSKEY missing from zone apex.

3

Security Scoring Formula (100-Point Scale)

The numerical score represents institutional readiness and cryptographic robustness across all 6 verification layers:

Inspection Layer / PillarWeight (Points)Evaluation Condition
1. Domain Resolution (A/AAAA)+10 ptsAuthoritative servers return valid A or AAAA address records.
2. Apex DNSKEY Presence+20 ptsAt least one valid DNSKEY RRset published at zone apex.
3. Parent DS Record Presence+20 ptsParent registry (.UG or gTLD) publishes matching Delegation Signer record.
4. DS / DNSKEY Cryptographic Match+20 ptsCalculated SHA digest of Apex KSK exactly matches Parent DS digest.
5. Active RRSIG Signatures+20 ptsAll RRSIG timestamps valid (current time > Inception AND < Expiration).
6. Chain of Trust Root Link+10 ptsFull cryptographic hierarchy verified back to ICANN root trust anchor.
4

.UG Namespace Scope & Sampling Transparency

We maintain total transparency regarding sample scope: while Uganda's national domain registry (.UG) comprises approximately ~14,500 total domains across all commercial entities, personal blogs, and parked names, this observatory explicitly curates and tracks a core national sample of 240+ high-impact institutional domains.

Government & MDAs: Ministries, Departments, and Agencies (`*.go.ug`).
Banking & Financial Services: Commercial Banks, Microfinance institutions, Central Bank (`bou.or.ug`).
Telecoms & Critical Infrastructure: Mobile Network Operators (`mtn.co.ug`, `airtel.co.ug`), ISPs, IXPs.
Universities & Research: Public and Private Higher Education Institutions (`*.ac.ug`).