Over the next two chapters, we'll take a look at a wider scope of domain security:
- Protecting your domains from unauthorized manipulation via a required vendor, such as a registrar or managed DNS provider platform
- Ensuring the validity of your zone data (DNSSEC)
- Mitigating brute-force attacks, such as Denial-of-Service (DDoS)
We'll also briefly touch on approaches to secure the transport between authoritative servers and resolvers, such as DNSCurve.
By the end of this chapter, you should have a set of basic principles that will enhance the security of your domains. You will also understand DNSSEC, what it is, why you may want to use it, and what is involved in doing so.
Then, in the following chapter, we'll continue the discussion with a look at DDoS mitigation strategies.