With DNSSEC, each answer to a DNS query is digitally signed and can be fully validated against public keys at every link in the chain

ICANN and the DNS root system operators plan to sign the root zone

which will make full end-to-end DNSSEC validation possible.


