| RFC | Status | Title |
| RFC2782 | PS | A DNS RR for specifying the location of services (DNS
SRV) |
| RFC2845 | Standard | Secret Key Transaction Authentication for DNS (TSIG) |
| RFC2929 | BCP | Domain Name System (DNS) IANA Considerations |
| RFC2930 | PS | Secret Key Establishment for DNS (TKEY RR) |
| RFC2931 | PS | DNS Request and Transaction Signatures ( SIG(0)s ) |
| RFC3007 | PS | Secure Domain Name System (DNS) Dynamic Update |
| RFC3008 | PS | Domain Name System Security (DNSSEC) Signing Authority |
| RFC3090 | PS | DNS Security Extension Clarification on Zone Status |
| RFC3110 | PS | RSA/SHA-1 SIGs and RSA KEYs in the Domain Name System
(DNS) |
| RFC3123 | E | A DNS RR Type for Lists of Address Prefixes (APL RR) |
| RFC3197 | I | Applicability Statement for DNS MIB Extensions |
| RFC3225 | PS | Indicating Resolver Support of DNSSEC |
| RFC3226 | PS | DNSSEC and IPv6 A6 aware server/resolver message size
requirements |
| RFC3363 | I | Representing IPv6 addresses in DNS |
| RFC3364 | I | Tradeoffs in DNS support for IPv6 |
| RFC3425 | PS | Obsoleting IQUERY |
| RFC3445 | PS | Limiting the Scope of the KEY Resource Record out |
| RFC3596 | Standard | DNS Extensions to support IP version 6 |
| RFC3597 | PS | Handling of Unknown DNS Resource Record (RR) Types |
| RFC3645 | Standard | GSS Algorithm for TSIG (GSS-TSIG) |
| RFC3655 | Standard | Redefinition of DNS AD bit |
| RFC3658 | Standard | Delegation Signer Resource Record |
| RFC3755 | Standard | Legacy Resolver Compatibility for Delegation Signer |
| RFC3757 | Standard | KEY RR Secure Entry Point Flag |
| RFC3833 | I | Threat Analysis Of The Domain Name System |
| RFC3845 | Standard | DNS Security (DNSSEC) NextSECure (NSEC) RDATA Format |
| RFC4033 | Standard | DNS Security Introduction and Requirements |
| RFC4034 | Standard | Resource Records for the DNS Security Extensions |
| RFC4035 | Standard | Protocol Modifications for the DNS Security Extensions |
| RFC4343 | Standard | Domain Name System (DNS) Case Insensitivity
Clarification |
| RFC4398 | PS | Storing Certificates in the Domain Name System (DNS) |
| RFC4470 | PS | Minimally Covering NSEC Records and DNSSEC On-line
Signing |
| RFC4471 | E | Derivation of DNS Name Predecessor and Successor |
| RFC4509 | PS | Use of SHA-256 in DNSSEC Delegation Signer (DS) Resource
Records (RRs) |
| RFC4592 | PS | The Role of Wildcards in the Domain Name System |
| RFC4635 | PS | HMAC SHA (Hashed Message Authentication Code, Secure
Hash Algorithm) TSIG Algorithm Identifiers |
| RFC4701 | PS | A DNS Resource Record (RR) for Encoding Dynamic Host
Configuration Protocol (DHCP) Information (DHCID RR) |
| RFC4795 | I | Link-local Multicast Name Resolution (LLMNR) |
| RFC4955 | PS | DNS Security (DNSSEC) Experiments |
| RFC4956 | E | DNS Security (DNSSEC) Opt-In |
| RFC4986 | I | Requirements Related to DNS Security (DNSSEC) Trust
Anchor Rollover |
| RFC5001 | PS | DNS Name Server Identifier Option (NSID) |
| RFC5011 | PS | Automated Updates of DNS Security (DNSSEC) Trust Anchors |
| RFC5155 | PS | DNS Security (DNSSEC) Hashed Authenticated Denial of
Existence |
| RFC5395 | BCP | Domain Name System (DNS) IANA Considerations |
| RFC5452 | PS | Measures for Making DNS More Resilient against Forged
Answers |
| RFC5625 | BCP | DNS Proxy Implementation Guidelines |
| RFC5702 | PS | Use of SHA-2 algorithms with RSA in DNSKEY and RRSIG
Resource Records for DNSSEC |