RFC 2065:Domain Name System Security Extensions
RFC-Ref

DNS server


Click on the red underlined text to get to the source

... Under conditions described in Section 3.7, security aware DNS servers will automatically attempt to return KEY resources as additional information, along with those resource records ...
... in the current DNS and requests with a non-empty additional information section are ignored by almost all current DNS servers. However, this syntax for signing requests is defined in connection ...


... transaction authentication service if the owner name is a DNS server host. It could also be used in an IP ...
... Security aware DNS servers MUST include KEY RRs as additional information in responses where appropriate including the following: ...


... WARNING: Request SIGs are unnecessary for currently defined queries and will cause almost all existing DNS servers to completely ignore a query. However, such SIGs may be needed to authenticate ...
... Security aware DNS servers MUST, for every authoritative RR the query ...
... (Section 4.1.4). Such SIG RRs are signed by the DNS server originating the response. Although the signer field MUST be the ...



Google
Web
RFC-Ref