The global DNS root server naming scheme, unchanged since 1995, is undergoing its first major technical review in nearly a decade. A recent study commissioned by ICANN’s Root Server System Advisory Committee (RSSAC) has tested six alternative naming schemes for the 13 root servers, with results that challenge long-held assumptions about backward compatibility and security trade-offs.
Root servers, identified by letters A through M under the root-servers.net domain, form the foundation of the DNS hierarchy. While only 13 distinct names exist, each represents a globally distributed anycast cluster operated independently. The current naming structure creates a circular dependency: resolvers must locate root servers to bootstrap DNS, yet the root server names reside within a domain that itself requires root server resolution. This paradox is resolved through an unsigned "priming" response containing glue records, a method that has remained static since its 1995 implementation.
What the study measured
The RSSAC 028 study, initiated in 2017, focused on two primary objectives: evaluating the feasibility of DNSSEC-signing the root server naming domain and assessing the impact of alternative naming schemes on the priming response size. Researchers from NLnet Labs and SIDN Labs tested six candidate naming structures, measuring their effect on the 512-byte UDP packet limit that has governed DNS priming since the protocol’s early days.
Contrary to expectations, the study found that DNSSEC-signed priming responses could remain within the 512-byte limit across all tested naming schemes. This discovery addresses a key concern that had stalled progress for nearly a decade—the fear that cryptographic signatures would push packet sizes beyond legacy system compatibility. The findings suggest that the technical barrier to securing root server naming may be lower than previously assumed.
Why the results matter
The current unsigned priming response presents a security vulnerability that has persisted for nearly 30 years. While the response is carefully curated to minimize risk, its lack of cryptographic validation leaves it susceptible to manipulation. The study’s results indicate that DNSSEC signing could be implemented without breaking compatibility with older resolvers, a critical consideration for the internet’s foundational infrastructure.
Background:
The DNS root zone contains delegations for all top-level domains (TLDs) and is served by 13 logical root servers (A-M). These servers are not single machines but globally distributed anycast clusters. The root-servers.net domain, created in 1995, has never been DNSSEC-signed, leaving its priming responses vulnerable to tampering.
Willem Toorop, a researcher at NLnet Labs, discussed the implications in a recent APNIC podcast. He noted that while the technical path forward appears clearer, the DNS community’s cautious approach means any changes would still require years of further testing and consensus-building. The study also revealed that some naming schemes performed better than others in terms of packet size efficiency, though all remained within acceptable limits.
What comes next
The study’s findings have reignited discussions within ICANN and the broader DNS operations community. While no immediate changes to root server naming are expected, the results provide a data-driven foundation for future policy decisions. The next steps will likely involve additional testing of the most promising naming schemes, particularly those that balance security improvements with minimal disruption to existing infrastructure.
For operators, the study serves as a reminder that foundational DNS components are not static. While the root server system has remained largely unchanged for decades, the technical and security landscape continues to evolve. The possibility of DNSSEC-signed root server names—once considered a distant prospect—now appears more achievable than previously thought.
Companies mentioned
Automated pipeline · Domains
Synthesized from 1 industry feed on 9 Jul 2026. Passed independent editor verification (score 88/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — New story No recent or in-pipeline article covers DNS root server name choices or RSSAC 028.
- Checking for duplicates — New story pre_write:; No recent or in-pipeline article covers DNS root server name choices or RSSAC 028 testing.
- Writing the article — Draft created article_id=302 slug=dns-root-server-naming-test-yields-unexpected-results
-
Editor review — Approved
- Score: 88/100
- Factual grounding: The draft states the study was 'initiated in 2017' — Source 1 says RSSAC 028 is 'a 2017 technical analysis' but does not specify the initiation year. The 2017 date is not explicitly confirmed as the study's start date in the source text.
- Style compliance: The standfirst ('RSSAC 028 study finds DNSSEC signing of root server names may not break legacy systems') is slightly misleading — the study tested six naming schemes, not just DNSSEC signing. The standfirst should reflect the broader scope of the study.
- No copied phrasing: The phrase 'circular dependency: resolvers must locate root servers to bootstrap DNS, yet the root server names reside within a domain that itself requires root server resolution' closely mirrors Source 1's 'circular dependency. A newly bootstrapped DNS resolver needs to locate a root server, but the names of the root servers are within the root-servers.net domain...'. Restructure to avoid echoing the source's phrasing.
- Quote integrity: No verbatim quote from Willem Toorop is provided in Source 1, so the attribution ('He noted that while the technical path forward appears clearer...') should not be presented as a direct quote. Either find a verbatim quote in the source or rephrase as a paraphrased attribution without quotation marks.
- Generating reader Q&A — Generated 4 items
- Assigning hero image — Reused library image reused image #14
- Linking related stories — Linked 2 relations from 248 candidates
- Publishing — Published dns-root-server-naming-test-yields-unexpected-results
- Mastodon — Posted https://mstdn.social/@hostingpaper/116887518026517724




Discussion · coming soon
Be the first to join the thread when community discussion launches.