STIGQter STIGQter: STIG Summary:

Microsoft Windows Server Domain Name System (DNS) Security Technical Implementation Guide

Version: 2

Release: 5 Benchmark Date: 01 Jul 2026

CheckedNameTitle
☐SV-259334r960735_ruleThe Windows DNS Server must restrict incoming dynamic update requests to known clients.
☐SV-259335r1156947_ruleThe Windows DNS Server must be configured to record who added/modified/deleted DNS zone information.
☐SV-259336r1156948_ruleThe Windows DNS Server must notify the DNS administrator in the event of an error validating another DNS server's identity.
☐SV-259337r1156965_ruleThe Windows DNS Server log must be enabled.
☐SV-259338r1028386_ruleThe "Manage auditing and security log" user right must be assigned only to authorized personnel.
☐SV-259339r961104_ruleThe validity period for the Resource Record Signatures (RRSIGs) covering the Delegation Signer (DS) Resource Record (RR) for a zone's delegated children must be no less than two days and no more than one week.
☐SV-259340r1156964_ruleThe Windows DNS name servers for a zone must be geographically dispersed.
☐SV-259341r1156949_ruleThe Windows DNS Server must prohibit recursion on authoritative name servers for which forwarders have not been configured for external queries.
☐SV-259342r1156949_ruleForwarders on an authoritative Windows DNS Server, if enabled for external resolution, must forward only to an internal, non-Active Directory (AD)-integrated DNS server or to the DOD Enterprise Recursive Services (ERS).
☐SV-259343r1156949_ruleThe Windows DNS Server with a caching name server role must restrict recursive query responses to only the IP addresses and IP address ranges of known supported clients.
☐SV-259344r1137675_ruleThe Windows DNS Server must implement cryptographic mechanisms to detect changes to information during transmission.
☐SV-259345r961863_ruleThe validity period for the Resource Record Signatures (RRSIGs) covering a zone's DNSKEY RRSet must be no less than two days and no more than one week.
☐SV-259346r1156952_ruleNSEC3 must be used for all internal DNS zones.
☐SV-259347r961863_ruleThe Windows DNS Server's zone files must have NS records that point to active name servers authoritative for the domain specified in that record.
☐SV-259348r1156953_ruleAll authoritative name servers for a zone must be located on different network segments.
☐SV-259349r961863_ruleAll authoritative name servers for a zone must have the same version of zone information.
☐SV-259350r1156954_ruleThe Windows DNS Server must be configured to enable DNSSEC Resource Records (RRs).
☐SV-259351r961863_ruleThe digital signature algorithm used for DNSSEC-enabled zones must be FIPS-compatible.
☐SV-259352r961863_ruleFor zones split between the external and internal sides of a network, the resource records (RRs) for the external hosts must be separate from the RRs for the internal hosts.
☐SV-259353r961863_ruleIn a split DNS configuration between the external and internal networks, the external name server must be configured to not be reachable from inside resolvers.
☐SV-259354r961863_rulePrimary authoritative name servers must be configured to only receive zone transfer requests from specified secondary name servers.
☐SV-259355r1156956_ruleThe Windows DNS Servers zone database files must not be accessible for edit/write by users and/or processes other than the Windows DNS Server service account and/or the DNS database administrator.
☐SV-259356r961863_ruleThe Windows DNS Server must implement internal/external role separation.
☐SV-259357r961863_ruleThe Windows DNS Server authoritative for local zones must only point root hints to the DNS servers that host the internal root domain.
☐SV-259358r961863_ruleThe Windows DNS Servers zone files must not include resource records that resolve to a fully qualified domain name residing in another zone.
☐SV-259359r1156962_ruleThe Windows DNS Server's zone files must not include CNAME records pointing to a zone with lesser security for more than six months.
☐SV-259360r961863_ruleNonroutable IPv6 link-local scope addresses must not be configured in any zone.
☐SV-259361r1018796_ruleAAAA addresses must not be configured in a zone for hosts that are not dual stack.
☐SV-259363r960999_ruleThe Windows DNS Server must uniquely identify the other DNS server before responding to a server-to-server transaction.
☐SV-259364r961503_ruleThe secondary Windows DNS name servers must cryptographically authenticate zone transfers from primary name servers.
☐SV-259365r960735_ruleThe Windows DNS primary server must only send zone transfers to a specific list of secondary name servers.
☐SV-259366r1156946_ruleThe Windows DNS Server must provide its identity with returned DNS information by enabling DNSSEC and TSIG/SIG(0).
☐SV-259367r1212357_ruleThe Windows DNS Server must be configured to enforce authorized access to the corresponding private key.
☐SV-259368r1212359_ruleThe Windows DNS Server key file must be owned by the account under which the Windows DNS Server service is run.
☐SV-259370r961041_ruleThe private key corresponding to the zone signing key (ZSK) must only be stored on the name server that does support dynamic updates.
☐SV-259371r1212361_ruleThe Windows DNS Server must implement a local cache of revocation data for PKI authentication.
☐SV-259372r961863_ruleThe salt value for zones signed using NSEC3 resource records (RRs) must be changed every time the zone is completely re-signed.
☐SV-259373r961101_ruleThe Windows DNS Server must include data origin with authoritative data the system returns in response to external name/address resolution queries.
☐SV-259374r1156950_ruleThe Windows DNS Server's IP address must be statically defined and configured locally on the server.
☐SV-259375r1156950_ruleThe Windows DNS Server must return data information in response to internal name/address resolution queries.
☐SV-259376r987696_ruleThe Windows DNS Server must use DNSSEC data within queries to confirm data origin to DNS resolvers.
☐SV-259377r961581_ruleWINS lookups must be disabled on the Windows DNS Server.
☐SV-259378r961581_ruleThe Windows DNS Server must use DNSSEC data within queries to confirm data integrity to DNS resolvers.
☐SV-259379r961104_ruleThe Windows DNS Server must be configured with the Delegation Signer (DS) Resource Records (RR) carrying the signature for the RR that contains the public key of the child zone.
☐SV-259380r961107_ruleThe Windows DNS Server must enforce approved authorizations between DNS servers using digital signatures in the Resource Record Set (RRSet).
☐SV-259381r961107_ruleThe Name Resolution Policy Table (NRPT) must be configured in Group Policy to enforce clients to request DNSSEC validation for a domain.
☐SV-259382r961107_ruleThe Windows DNS Server must be configured to validate an authentication chain of parent and child domains via response data.
☐SV-259383r961107_ruleTrust anchors must be exported from authoritative Windows DNS Servers and distributed to validating Windows DNS Servers.
☐SV-259384r961107_ruleAutomatic Update of Trust Anchors must be enabled on key rollover.
☐SV-259385r961584_ruleThe Windows DNS secondary servers must request data origin authentication verification from the primary server when requesting name/address resolution.
☐SV-259386r961587_ruleThe Windows DNS secondary server must request data integrity verification from the primary server when requesting name/address resolution.
☐SV-259387r961590_ruleThe Windows DNS secondary server must validate data integrity verification on the name/address resolution responses received from primary name servers.
☐SV-259388r961593_ruleThe Windows DNS secondary server must validate data origin verification authentication on the name/address resolution responses received from primary name servers.
☐SV-259389r1043178_ruleThe Windows DNS Server must protect the authenticity of zone transfers via transaction signing.
☐SV-259390r1043178_ruleThe Windows DNS Server must protect the authenticity of dynamic updates via transaction signing.
☐SV-259391r1043178_ruleThe Windows DNS Server must protect the authenticity of query responses via DNSSEC.
☐SV-259392r961596_ruleThe Windows DNS Server must use an approved DOD PKI certificate authority.
☐SV-259393r1028387_ruleThe Windows DNS Server must protect secret/private cryptographic keys while at rest.
☐SV-259394r961599_ruleThe Windows DNS Server must only contain zone records that have been validated annually.
☐SV-259395r961152_ruleThe Windows DNS Server must restrict individuals from using it for launching denial-of-service (DoS) attacks against other information systems.
☐SV-259396r961155_ruleThe Windows DNS Server must use DNS Notify to prevent denial of service (DoS) through increase in workload.
☐SV-259397r961632_ruleThe Windows DNS Server must protect the integrity of transmitted information.
☐SV-259398r961638_ruleThe Windows DNS Server must maintain the integrity of information during preparation for transmission.
☐SV-259399r961641_ruleThe Windows DNS Server must maintain the integrity of information during reception.
☐SV-259400r1137676_ruleThe Windows DNS Server must implement NIST FIPS-validated cryptography for provisioning digital signatures, generating cryptographic hashes, and protecting unclassified information requiring confidentiality.
☐SV-259401r961158_ruleThe Windows DNS Server must be configured to only allow zone information that reflects the environment for which it is authoritative, including IP ranges and IP versions.
☐SV-259402r1156951_ruleThe Windows DNS Server must follow procedures to re-role a secondary name server as the primary name server if the primary name server permanently loses functionality.
☐SV-259403r1001264_ruleThe DNS Name Server software must be configured to refuse queries for its version information.
☐SV-259404r1001265_ruleThe HINFO, RP, TXT, and LOC RR types must not be used in the zone SOA.
☐SV-259405r1156945_ruleThe Windows DNS Server must, when a component failure is detected, activate a notification to the system administrator.
☐SV-259406r961734_ruleThe Windows DNS Server must verify the correct operation of security functions upon startup and/or restart, upon command by a user with privileged access, and/or every 30 days.
☐SV-259407r961734_ruleThe Windows DNS Server must verify the correct operation of security functions upon system startup and/or restart, upon command by a user with privileged access, and/or every 30 days.
☐SV-259408r961737_ruleThe Windows DNS Server must log the event and notify the system administrator when anomalies in the operation of the signed zone transfers are discovered.
☐SV-259409r961185_ruleThe Windows DNS Server must be configured to notify the information system security officer (ISSO), information system security manager (ISSM), or DNS administrator when functionality of DNSSEC/TSIG has been removed or broken.
☐SV-259410r1156963_ruleA unique Transaction Signature (TSIG) key must be generated for each pair of communicating hosts.
☐SV-259411r961062_ruleThe DNS server implementation must employ strong authenticators in the establishment of nonlocal maintenance and diagnostic sessions.
☐SV-259412r961125_ruleIn the event of a system failure, the Windows DNS Server must preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes.
☐SV-259414r1156961_ruleThe private keys corresponding to both the zone signing key (ZSK) and the key signing key (KSK) must not be kept on the DNSSEC-aware primary authoritative name server when the name server does not support dynamic updates.
☐SV-259415r960948_ruleThe Windows DNS Server audit records must be backed up at least every seven days onto a different system or system component than the system or component being audited.
☐SV-259416r961863_ruleIn a split DNS configuration, where separate name servers are used between the external and internal networks, the internal name server must be configured to not be reachable from outside resolvers.
☐SV-259417r961155_ruleWindows DNS response rate limiting (RRL) must be enabled.