Slide 27
Slide 27 text
NSEC
Zone entries are sorted alphabetically, and the
NextSECure(NSEC) records point to the record after
the one you looked up
Basically, NSEC record says, “there are no
subdomains between sub-domain X and sub-
domain Y.”
$ dig +dnssec @ns1.insecuredns.com firewallll.insecuredns.com
... snipped ...
firewall.insecuredns.com. 604800 IN NSEC mail.insecuredns.com. A RRSIG NSEC
... snipped ...