Skip to content

10 NIST DNS Security Insights from SP 800-81 Co-Author Scott Rose

These NIST DNS Security Insights from the webinar, featuring Scott Rose, Yaelle Harel, and Andreas Taudte, show why DNS is a vital control point that can help stop attacks before they happen.

September 3, 2026 | Written by: Yaëlle Harel |

Summary

Scott Rose Discusses Nist Dns Security Insights

What Are the Most Important NIST DNS Security Insights?

The most important insights are to treat DNS as an active part of enterprise security, understand how it is currently used, apply protective controls, use DNS telemetry to inform policy, and validate the environment continuously.

Key Takeaways

  • Treat DNS as an active security control, not background infrastructure.
  • Map DNS roles, resolution paths, ownership, and telemetry first.
  • Combine immediate improvements with continuous validation.

NIST SP 800-81 in Brief—and Why Hearing from Scott Rose Matters

NIST SP 800-81 provides guidance for securing and operating DNS services. Its latest revision moves beyond securing individual servers and looks at DNS as an enterprise service spanning authoritative DNS, recursive resolution, endpoint stub resolvers, telemetry, governance, and policy enforcement.

Scott Rose is a NIST computer scientist working on core internet technologies, a co-author of SP 800-81, and a contributor to NIST’s zero trust guidance. In EfficientIP’s webinar, he joined Andreas Taudte, Senior Technical  Marketing Manager at EfficientIP, who added practical enterprise experience to Rose’s explanation of the guide.

Insight 1: DNS Is More Important Than Ever

Cloud computing and IPv6 deployment are increasing organizations’ reliance on DNS and named services. That reliance is especially visible in service-based and microservice architectures running on virtualized platforms, where IP addresses can be ephemeral and change frequently. Rose pointed to 5G and 6G mobile telecom architectures as one example: services are discovered by name rather than tied to fixed addresses.

Rose also noted that DNS already carries policy information, for example for email, while emerging work is exploring how security and other information about AI agents could be associated with DNS. This reinforces DNS’s role as a central lookup and discovery mechanism.

That also raises the security stakes. Compromising DNS can redirect users or alter information before protections such as HTTPS take effect. As Rose put it, “If you can subvert them at the DNS layer, you stop them before they even make the connection.”

Simplify & Secure Your Network

Our goal is to help companies face the challenges of modern infrastructures and digital transformation.

Insight 2: Protective DNS Can Stop Threats Earlier

Protective DNS uses the DNS layer to monitor or block suspicious connections before they become larger incidents. Rose explained that enterprises can “take action using that DNS layer to prevent a lot of attacks before they get severe or propagate.”

Andreas added that DNS security also depends on access control, patching, logging, governance, and DNS hygiene—not only DNSSEC or encrypted DNS.

Insight 3: DNS Plays Two Roles in Zero Trust

Rose said DNS plays two roles in zero trust: it is a data source and a policy enforcement point.

DNS activity can reveal unauthorized behavior and help refine security policy. It can also prevent connections, disrupt command and control, and help stop data exfiltration. Endpoint stub resolvers must be controlled as well, or they may bypass enterprise policy.

Insight 4: Start by Mapping How DNS Works Today

Rose’s first recommendation was discovery: “map, or find out how you’re actually using your DNS infrastructure today.”

Teams should identify authoritative and recursive services, endpoint stubs, cloud DNS, owners, resolution paths, controls, and logging. He called the DNS query stream “a vital data feed.”

Scott also stressed the need for buy-in and communication between DNS administration and cybersecurity teams, bringing DNS operations into the wider security program rather than treating DNS as an isolated infrastructure service.

Andreas made the recommendation practical: DNS resolution should be predictable. Teams should select a user, server, or cloud workload and trace a query from source to answer, identifying the resolvers and policies involved, what is logged, and who owns each part of the path. The exercise can also reveal protective DNS or DNSSEC capabilities that are already available but not configured. Comparing the findings with SP 800-81 provides the basis for a prioritized roadmap.

Insight 5: DNS Telemetry Is a Window into the Enterprise

When the enterprise controls its DNS infrastructure and resolution path, DNS can provide valuable visibility even when application traffic is encrypted. As Rose put it, “You always look up a DNS name first.”

Query data can expose tunneling, data exfiltration, command-and-control activity, and affected assets. His warning was clear: “If you’re missing DNS data and telemetry, you’re missing real key insights into what’s going on in your infrastructure.”

Andreas recommended sharing this intelligence with other security tools.

Insight 6: DNSSEC and Encrypted DNS Solve Different Problems

DNSSEC protects the integrity and authenticity of DNS data through digital signatures. DoH, DoT, and DoQ protect the confidentiality of query-response traffic.

Enterprises may need both, but unmanaged encrypted DNS can reduce visibility or send internal queries to external resolvers. The goal is to improve privacy without losing necessary enterprise control.

Insight 7: Separate DNS Roles and Responsibilities

Authoritative DNS, recursive DNS, and stub resolvers have different trust boundaries and attack surfaces. Separating them helps assign controls and ownership.

One team may manage authoritative zones and DNSSEC signing, while another handles validation, protective DNS, and traffic analysis. The guide’s role-based structure also helps administrators focus on the guidance most relevant to them.

Insight 8: Combine Immediate Improvements with Architectural Change

Not every DNS security improvement requires an architectural overhaul. Organizations can immediately review administrator access, patching and monitoring, logging, audit trails, workflows, and DNS hygiene. These checks can be performed on the existing infrastructure and used to assess risk and set priorities. Where the current platform already supports automated DNSSEC, a pilot in a low-risk-zone can provide another practical starting point.

Longer term work begins where the DNS service itself must change, such as separating authoritative and recursive roles, establishing hybrid resolution across on-premises and cloud environments, or expanding enterprise controlled encrypted DNS and protective DNS coverage.

The objective is to strengthen current controls now while planning the architectural changes that require broader design and deployment work.

Insight 9: Continuous Validation Moves DNS Toward Zero Trust

DNS security cannot be completed once and forgotten. Andreas recommended regular reviews of resolution paths, ownership, records, controls, and policies.

Rose connected this to zero trust: organizations should keep “reevaluating and making changes to the posture in response to things.” Continuous validation turns DNS security from a static deployment into an adaptive control.

Insight 10: Post-Quantum Cryptography Is an Emerging DNS Security Challenge

Rose identified post-quantum cryptography as an emerging issue. Algorithms have not yet been defined for use with DNSSEC, and UDP message-size limits make post-quantum cryptography more difficult to deploy.

Future guidance may need to address post-quantum algorithms for DNSSEC and encrypted DNS transports as standards and deployments mature.

Scott Rose’s Final Message: Don’t Forget About DNS

Rose closed with the webinar’s clearest takeaway: “Don’t forget about DNS.”

DNS can show what is happening across the organization, map data flows, and enforce policy before connections are established. As he explained, it can help enterprises “stop some attacks before they even happen.”

How EfficientIP Can Help Put the Guidance into Practice

EfficientIP helps organizations apply SP 800-81 across DNS governance, architecture, protection, and observability:

  • SOLIDserver DDI provides centralized management of multivendor DNS environments, with workflows, auditing, DNSSEC management, and resilient architecture.
  • EfficientIP’s 360° DNS Security turns DNS into an active security control by combining protective DNS, AI-driven detection, DNS-centric threat intelligence, and automated response to stop threats earlier, strengthen visibility, and support continuous security improvement.
  • DNS Intelligence Center and DDI Observability Center provide operational and security insights that help teams understand DNS activity and continuously assess their DNS environment.
  • Integrations with the wider security ecosystem help teams share DNS intelligence and coordinate detection and response across security tools.

Together, these capabilities help organizations strengthen existing controls, improve visibility, and continuously validate their DNS security posture.

FAQ

Watch the NIST DNS Security Webinar

Hear directly from NIST SP 800-81 co-author Scott Rose and EfficientIP’s Andreas as they discuss protective DNS, zero trust, DNS telemetry, encrypted DNS, and practical implementation priorities.

Talk to an expert