If you want to know whether a domain is signed with DNSSEC, don’t ask what it’s for or how secure the operator is. Ask what comes after the last dot. That single character — the TLD — predicts DNSSEC signing better than anything about the domain itself.

Line up the numbers and it stops looking like a security story at all. Verisign runs its own DNSSEC scoreboard, and on it .com sits at roughly 4% signed. .net is a hair higher. Meanwhile the Netherlands’ .nl is around 60%. Sweden’s .se and the Czech .cz are both above half. These are not exotic ccTLDs run by hobbyists — .nl alone has millions of domains, more than most gTLDs will ever see. So the same protocol, the same registrars, the same registration software, produces a roughly fifteen-fold difference in adoption depending purely on which registry the name lives under.

The protocol is identical everywhere. The economics are not. And the economics win.

The thing everyone blames is not the thing

The standard explanation for DNSSEC’s two-decade crawl is that it’s operationally miserable, and that part is true. Keys expire. A KSK rollover means coordinating a DS record handoff with your parent zone, and if the timing slips your entire domain goes dark — not slow, not flaky, SERVFAIL for everything. I’ve written before that DNSSEC punishes mistakes with outages and rewards success with silence. All still true.

But operational misery is a constant. It’s just as miserable to sign a .nl domain as a .com domain — same crypto, same failure modes, same registrar interfaces. If difficulty were the whole story, adoption would be uniformly low everywhere. It isn’t. It’s low in some places and normal in others, and the line between them isn’t technical.

SIDN, the registry that runs .nl, has said the quiet part out loud: “the main driver of DNSSEC adoption has been incentivisation: schemes where registrars are charged lower fees for signed domain names than for unsigned domain names” — and “little happens when no such scheme is in place.” That’s the registry’s own read of its own data. Not “the protocol is hard.” Follow the money.

Where the money is

.nl is the cleanest case, because SIDN built an actual machine for it. SIDN’s first incentive scheme was a discount on signed names; at the start of 2015 it was folded into a broader Registrar Scorecard: deploy modern standards, including DNSSEC, and SIDN pays you a rebate. The rebates aren’t symbolic, either; in 2018 they added up to more than 1.5 million euros. So a .nl registrar faces a concrete choice: automate DNSSEC across your customer base and collect, or skip it and leave money on the table. Most collected. Adoption went vertical.

SIDN puts Sweden’s .se, the Czech .cz, and Norway’s .no in the same group as .nl: zones past 50% signed, where the registry actively pushed signing with incentives and promotion. Different registries, different mechanics, same lever: make signing the cheaper or the default choice for the registrar, and more than half the zone follows.

Brazil is the instructive middle. Registro.br offers its own authoritative DNS hosting with DNSSEC built in, and by 2018 about a quarter of .br was signed — nearly all of it on those registry-operated nameservers. Not the 60% of a paid-rebate zone, not the 4% of a hands-off one. Make it built in, you get a quarter. Pay people, you get more than half. Do nothing, you get almost nobody. The curve is legible.

Then there’s the mandate lever, which is just economics wearing a uniform. The US government told itself to sign: OMB Memorandum M-08-23, back in 2008, ordered the .gov space signed on a deadline. When the choice is “sign or be out of compliance,” the operational misery suddenly becomes affordable. Adoption inside .gov jumped past what any comparable commercial slice managed, for the obvious reason that nobody was measuring the ROI — they were measuring the memo.

Signing is not the same as protection

Here’s the part that makes the low signing numbers genuinely frustrating rather than merely disappointing: the resolver side of DNSSEC is basically fine.

Signing and validation are two different halves. Signing is the authoritative side — the domain owner (really, the registry’s incentives) deciding to attach signatures. Validation is the resolver side — whether the DNS server answering your queries actually checks those signatures. And validation is in decent shape. APNIC Labs measures it continuously, and roughly a third of internet users worldwide sit behind a validating resolver. Google’s 8.8.8.8 and Cloudflare’s 1.1.1.1 validate. That means for a third of the planet, a signed domain is genuinely protected against forged answers — the resolver will refuse to hand over a record that doesn’t chain back to a trusted key.

So the machinery to use DNSSEC is deployed and running. A third of users are ready to check signatures that, for .com, 96% of domains never bothered to produce. We built the lock and handed out the keys, and then most of the doors shipped without a keyhole. The bottleneck was never the resolvers. It was whether anyone paid the registrars to sign, and for most of the namespace, nobody did.

Why the holdouts are rational

It would be easy to end on “so just add incentives everywhere,” but the registrars who don’t sign aren’t being lazy. They’re being risk-averse, and the risk is real, and it showed up again in the worst possible way not long ago.

On May 5, 2026, DENIC — the registry for Germany’s .de — ran a scheduled key rollover, and faulty code in the rollover generated three different key pairs that all carried the same key tag. Only one of them matched the published key, so only about a third of the zone’s signatures validated. The chain of trust broke at the top. Every validating resolver did exactly what it’s supposed to do: it refused the answers. For about three hours, as cached records expired, a growing share of .de became unreachable for anyone behind a validating resolver — and not just signed domains: unsigned .de names failed too, because the records that prove a delegation exists were now bogus. Not the misconfigured ones. The country’s TLD, taken down by its own security. Some large resolver operators, Cloudflare among them, temporarily suspended validation for .de to get their users back online while DENIC fixed the signatures.

This is the same failure mode that took nasa.gov offline for Comcast’s validating users back in 2012, scaled up to a national TLD. And it’s the entire argument against signing, made vivid: a registrar weighing DNSSEC is weighing a small, abstract protection against cache poisoning versus a small chance of taking their customers completely dark through no fault of the customers. Without a rebate tilting that math, “no” is a defensible answer.

Which is why the incentive schemes matter beyond the accounting. When SIDN pays for signing, it isn’t just bribing registrars — it’s buying down the perceived risk, funding the automation that makes rollovers boring instead of terrifying. The money doesn’t just reward signing. It pays for signing to be done well enough that the DENIC scenario stays rare.

Twenty years in, DNSSEC’s map isn’t drawn by cryptographers or CISOs. It’s drawn by whichever registries decided to open their wallets. Show me a TLD’s adoption rate and I’ll tell you its pricing policy, and I’ll almost never have to mention the protocol at all.