ToolHop.

ADVERT

NSEC3PARAM Checker

Fetch NSEC3PARAM values to review the hashing algorithm, salt, and iteration count used for DNSSEC denial of existence.

How to use this tool

  1. Query NSEC3PARAM records for the zone.
  2. Inspect algorithm, iterations, and salt values returned by DNS.
  3. Compare parameters with signer policy and active NSEC3 records.

Parameter checks

  • Validate hash algorithm and iteration count against expected settings.
  • Review salt changes during rollover and maintenance events.
  • Use TTL to estimate propagation timing for parameter updates.

Operational guidance

  • High iteration values can increase resolver workload and latency.
  • Salt changes generally require full zone resigning and careful rollout.
  • Keep NSEC3PARAM and generated NSEC3 chain settings in sync.

FAQ

What does iteration count affect?
It controls repeated hashing rounds, trading off brute-force resistance versus resolver processing cost.
When should salt be rotated?
Rotate on policy or incident requirements, and ensure the zone is resigned so updated hashes propagate correctly.
Why is algorithm value often 1?
Value 1 maps to SHA-1 in RFC 5155 and remains the common NSEC3 algorithm value in deployed zones.

Resources

ADVERT

ADVERT