What problem does it solve?
It prevents insecure DNS deployments by converting DNSSEC, filtering, and tunneling checks into a structured, auditable assessment aligned to NIST SP 800-81 Rev 2 and CIS Controls v8.
Core Features & Use Cases
- DNSSEC posture review: Validates zone signing, key management (KSK/ZSK), DS publication, and NSEC/NSEC3 choices for authoritative servers, plus DNSSEC validation and trust anchor handling for recursive resolvers.
- Encrypted DNS transport review: Checks for correct DoT/DoH usage, detects plaintext forwarding risks, and evaluates browser DoH bypass exposure when filtering is enforced.
- Protective DNS and exfiltration detection: Verifies RPZ/filtering deployment (CIS 9.2), ensures update/logging hygiene, and generates detection readiness for DNS tunneling and data exfiltration patterns.
- Use Case: After DNSSEC rollout or during a suspected DNS tunneling incident, run this skill to produce a prioritized findings report mapped to control references and concrete remediation steps.
Quick Start
Run the dns-security skill against your DNS configuration directory by passing the path you want to analyze as the single argument.