What’s New in DNS in Windows Server 2012


Is used to help protect an organization’s DNS queries from interception and tampering

Uses cryptographic keys and digital signatures to ensure DNS responses are valid

Uses a number of new resource records to sign and publish keys

GlobalNames Zones

Can replace DNS search suffix lists on client computers

Enables the resolution of single label names

How to Configure DNSSEC

DNSSEC is simpler to deploy in Windows Server 2012 than in previous versions of Windows Server

To deploy DNSSEC:

Assign the DNS server role

Sign the zones

Configure trust anchor distribution points

Configure NRPT on clients


Uses CNAME records in a special forward lookup zone


More Information can be found  : http://technet.microsoft.com/en-us/library/jj200224.aspx

