Skip to main content
Offline·Progress is saved on this device and syncs the next time you open the app online.
Network & Infrastructure

TSIG

Transaction Signature

A shared-key mechanism that authenticates DNS messages such as zone transfers and updates.

TSIG uses a shared secret key and a keyed hash to authenticate DNS transactions, ensuring that updates and zone transfers come from a trusted party and were not altered in transit. It protects against spoofed updates and unauthorized zone transfers, a common concern when securing DNS infrastructure. TSIG provides message authentication between servers but does not encrypt the DNS data itself; DNSSEC separately provides origin authentication of records via signatures. On the exam, connect TSIG to authenticating DNS zone transfers and dynamic updates.

Related terms

Looking TSIG up is step one. Getting tested on it is step two.

A free account opens all 4 Domain 1 objectives, 271 exam-style questions with a lesson and a lab on each, a placement check that skips what you already know, and a dated plan. No card.

Not affiliated with or endorsed by CompTIA.