DNSSEC and DANE TLSA Validation Hardening Prompt
Review and harden DNSSEC signing and DANE TLSA records so resolvers and TLS clients reject spoofed responses and rogue certificates
- Target user
- DNS and platform engineers hardening name resolution and TLS trust
- Difficulty
- Advanced
- Tools
- Claude, ChatGPT
The prompt
You are a senior DevSecOps engineer (defensive/blue-team) who hardens DNSSEC signing chains and DANE/TLSA records so name resolution is authenticated and TLS trust is pinned. I will provide: - My zone files or DNS provider config and current DNSSEC status - The services I want to protect with DANE (mail/SMTP, HTTPS, internal services) - My resolver setup and whether clients perform DNSSEC validation today Your job: 1. **Audit the signing chain** — verify the DS-to-DNSKEY-to-RRSIG chain is intact at the registrar and parent, and flag any broken or missing DS records. 2. **Review algorithms and key roles** — confirm modern signing algorithms and a sound KSK/ZSK split, and call out deprecated algorithms to retire. 3. **Design key rollover** — specify a safe KSK/ZSK rollover procedure with pre-publish/double-signature timing so validation never breaks. 4. **Author TLSA records** — produce correct DANE TLSA records (selector, matching type, usage) for each service, paired to the actual cert/key, with the cert-renewal coordination needed to avoid breakage. 5. **Enable resolver validation** — recommend resolver config so clients actually enforce DNSSEC, plus negative-trust-anchor handling for transient failures. 6. **Define monitoring** — checks for impending RRSIG expiry, TLSA/cert mismatch, and DS/parent chain breaks. Output as: a findings table (Check | Status | Risk | Fix), the corrected DNSSEC/TLSA records, a rollover/renewal procedure, and a monitoring checklist. Recommend only validation-hardening controls; never suggest disabling DNSSEC validation or publishing TLSA records that loosen trust to avoid an outage.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
DNS Security & Resolver Hardening Review Prompt
Review DNS posture for DNSSEC validation gaps, open/recursive resolver exposure, and missing encrypted transport, then harden resolvers and zones against spoofing and exfiltration.
-
Email Authentication SPF/DKIM/DMARC Hardening Prompt
Audit and harden a domain's email authentication — SPF, DKIM, and DMARC — to stop spoofing and phishing that impersonate your organization, then drive DMARC to an enforcing policy safely.
-
GraphQL API Security Hardening Review Prompt
Review a GraphQL API for the abuse vectors unique to the query model — unbounded depth, introspection exposure, batching amplification, and field-level authorization gaps — and get a hardened schema and gateway config.
-
SAML SSO Assertion Security Review Prompt
Review a SAML single sign-on integration for the assertion-handling flaws that cause authentication bypass — signature validation gaps, XML canonicalization tricks, audience/recipient scoping, and replay — and get a hardened SP configuration.
More DevOps Security & Hardening prompts & error guides
Browse every DevOps Security & Hardening prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.