DNSSEC Methodology & Verification Model.
Detailed technical documentation on our authoritative query engine, cryptographic chain verification rules, status-first overrides, and scoring algorithm.
Authoritative Live Resolution Engine
Unlike passive scanners that rely on recursive resolver caches, the Uganda DNS Observatory measurement engine performs direct, iterative cryptographic lookups starting from the ICANN Root Zone (.), down to Uganda's Country Code Top-Level Domain (.ug), and finally to the target domain's authoritative nameservers.
DS (Delegation Signer) records matching child target.DNSKEY records at zone apex.RRSIG signature records on Apex RRsets, checking inception and expiration timestamps.Key Tag 20326).Status-First Classification Overrides
To prevent false sense of security, our classification engine follows a strict Status-First Rule. If a domain suffers from a critical cryptographic failure (such as an expired RRSIG or a DS/DNSKEY mismatch), its classification is immediately locked to Bogus or Incomplete regardless of numerical points scored in other pillars.
Domain resolves, publishes valid DNSKEY records, has matching DS records at parent (.UG registry), active non-expired RRSIG signatures, and unbroken chain of trust from root.
Critical validation failure! Domain publishes DNSSEC records, but cryptographic verification fails due to DS/DNSKEY hash mismatch, expired RRSIGs, or broken trust chain. Resolvers will drop queries to this domain.
Domain resolves correctly, but publishes neither DS records at the parent nor DNSKEY records at apex. No DNSSEC protection is deployed.
Partial deployment detected. For example, DNSKEY published at apex but no DS record uploaded to .UG registry, or DS present at parent but DNSKEY missing from zone apex.
Security Scoring Formula (100-Point Scale)
The numerical score represents institutional readiness and cryptographic robustness across all 6 verification layers:
| Inspection Layer / Pillar | Weight (Points) | Evaluation Condition |
|---|---|---|
| 1. Domain Resolution (A/AAAA) | +10 pts | Authoritative servers return valid A or AAAA address records. |
| 2. Apex DNSKEY Presence | +20 pts | At least one valid DNSKEY RRset published at zone apex. |
| 3. Parent DS Record Presence | +20 pts | Parent registry (.UG or gTLD) publishes matching Delegation Signer record. |
| 4. DS / DNSKEY Cryptographic Match | +20 pts | Calculated SHA digest of Apex KSK exactly matches Parent DS digest. |
| 5. Active RRSIG Signatures | +20 pts | All RRSIG timestamps valid (current time > Inception AND < Expiration). |
| 6. Chain of Trust Root Link | +10 pts | Full cryptographic hierarchy verified back to ICANN root trust anchor. |
.UG Namespace Scope & Sampling Transparency
We maintain total transparency regarding sample scope: while Uganda's national domain registry (.UG) comprises approximately ~14,500 total domains across all commercial entities, personal blogs, and parked names, this observatory explicitly curates and tracks a core national sample of 240+ high-impact institutional domains.