As of 24 August 2026, APNIC data shows the resolvers used by Russian users validate DNSSEC signatures more often than the world average — 47.6% against 38.2%. Yet in our own check of 27 August 2026, exactly one .ru domain in 126 was signed, against 8.8% for .com and 19.3% for .org.
Hence the asymmetry: DNSSEC protects a Russian user more often than average, while a Russian site protects its visitor least of all. Signing and validation are different things and should not be conflated.
Free online tool — DNS lookup tool: instant results, no signup.
DNSSEC has two sides, and different numbers belong to each.
Signing is the domain owner’s job: the zone is signed and a DS record is published in the parent zone. Without it there is nothing to protect.
Validation is the resolver’s job — the ISP or public DNS the visitor happens to use. Without it nobody checks the signature.
The two cannot be mixed: a country can validate signatures widely and barely sign its own domains. That is exactly what we observe.
APNIC Labs measures the share of users whose resolver validates signatures, updated daily. As of 24 August 2026, 30-day window:
| Where | Validating | Partial | Sample |
|---|---|---|---|
| Russia | 47.6% | 37.9% | 51,599 |
| World | 38.2% | — | 594,884,345 |
Russian users get signature validation more often than the world average — by more than nine percentage points. That is the doing of ISPs and public resolvers, not of websites.
An important caveat about trends. The Russian figure swings year to year:
| August | 2021 | 2022 | 2023 | 2024 | 2025 | 2026 |
|---|---|---|---|---|---|---|
| Validating | 32.0% | 60.6% | 45.2% | 33.8% | 59.5% | 47.6% |
A two-fold spread. The reason lies in what is measured: users, not networks. When one large ISP switches validation on or off, the national share moves at once. Year-over-year "trends" on this series are meaningless — pick two points and you can show growth or decline at will.
On 27 August 2026 we checked for a DS record on domains users had brought to our tools — a dig DS query against a public resolver, on the registrable name:
| Zone | Checked | Signed | Share |
|---|---|---|---|
| .org | 135 | 26 | 19.3% |
| .net | 109 | 11 | 10.1% |
| .com | 137 | 12 | 8.8% |
| .ru | 126 | 1 | 0.8% |
Russian domains are signed roughly ten times less often than .com and twenty-four times less often than .org. In our sample exactly one domain of a hundred and twenty-six carries a signature.
Sampling caveat: these are domains somebody brought to our tools, not a random slice of the zone. Comparing zones to each other is sound — they were collected the same way — but the .ru level cannot stand in for "the Russian web". Not a single query failed, so "unsigned" here means an absent DS record rather than a failed lookup.
Put the two tables together. DNSSEC protects a Russian user more often than the average person on the planet. A Russian website protects its visitor less often than a site in any zone we compared.
The practical meaning: nearly half of Russian users reach the web through a resolver that will check a signature if one exists. For a domain owner that makes signing not a forward-looking gesture — the validating side is already in place and waiting.
And the converse: until the domain is signed, those 47.6% do nothing for it. There is nothing to check.
The data says how much, not why. Here we step past what was measured, so these are factors rather than a cause:
Check your own domain with the DNS lookup tool; what the records are and why each exists — what a domain is.
DNS (Domain Name System) translates domain names into IP addresses. DNS records are instructions that define where to route traffic, email, and how to verify domainownership.
Query all record types — A, AAAA, MX, NS, TXT, CNAME, SOA — in a single request.
Direct queries to authoritative servers. Results in milliseconds, no caching.
SPF, DKIM, and DMARC analysis to evaluate email protection against spoofing and phishing.
Save check results. Compare DNS records before and after registrar changes.
DNS check after deploy
SPF/DKIM/DMARC audit
DNS config audit
DNS zone control
v=spf1 TXT record.DNS check history, API keys and DNS change monitoring.
Sign up freeThree factors: (1) registrars (REG.RU, Timeweb) charge 500-2000₽/year for DNSSEC instead of offering it free; (2) FSB requires GOST R 34.10-2012, and most DNSKEY clients do not validate it — incompatible; (3) mass Bitrix hosting has no UI for DS updates.
The Czech registry CZ.NIC has been offering DNSSEC free and automatic since 2010. It is enabled by default at domain registration.
Enterno DNS Checker shows DNSKEY/DS/RRSIG and validation status. Or at the terminal: dig +dnssec +trace example.ru.
The domain becomes unresolvable for validating resolvers (1.1.1.1, 9.9.9.9) — clients get SERVFAIL. That is 25-40% of traffic for large sites. Fixed by committing the new DS to the TLD via your registrar.
Free plan — 10 monitors, checks every 5 min, no card required. Upgrade for 1-minute interval and multi-region monitoring.