2.6 DNS Configuration Flashcards
There are hundreds of generic top-level domains. What are top-level domains?
.com, .org, .net, etc
There are over 275 country code top-level domains. What are country code top-level domains?
.uk, .us, .ca, etc
How many DNS root server clusters are there?
13 root server clusters (over 1,000 actual servers)
What is DNS hierarchy?
DNS follows a path
www.
professormesser
.org
What are DNS records called?
Resource Records (RR)
What are RR for DNS?
resource records, the database records of domain name services
There are over ___ DNS record types
over 30 record types
(IP addresses, certificates, host alias names, etc)
DNS records are ____
important and critical configurations!
(check settings, backup, test)
What are DNS Address records?
Defines the IP address of a host (most popular query)
What are the 2 types of DNS Address records?
- A
- AAAA
What’s the difference between the 2 DNS Address record types?
A - for IPv4 addresses (modify this to change hostname to IP address resolution)
AAAA - for IPv6 addresses (same DNS server, different records)
What does MX record mean?
Mail exchanger record
What is an MX record?
determines the hostname for the mail server (not the IP address, the name)
What are Text records (TXT)?
Useful public information in human-readable text commonly used for email security like verification of domain ownership
(external email servers validate information from your DNS)
What is Sender Policy Framework (SPF)?
SPF protocol - a list of all servers authorized to send emails for a domain to prevent mail spoofing
(mail servers perform a check to see if incoming mail really did come from an authorized host)
What does DKIM stand for?
Domain Keys Identified Mail
What does DKIM do?
Domain Keys Identified Mail
Digitally signing a domain’s outgoing mail (public key is in a DKIM TXT record)
What does DMARC stand for?
Domain-based Message Authentication, Reporting, and Conformance
What is DMARC for?
validates emails and prevents unauthorized email use (spoofing) as an extension of SPF and DKIM
(you can decide what to do with emails that don’t validate through SPF or DKIM)
What does SPF stand for?
Sender Policy Framework