Offizielles MASTR Logo MASTR
Menü

Namen, Identität und Web-Inhalte

DNSSEC and HTTPS: two checks behind a wallet website

Authenticated name resolution and encrypted transport do not certify a financial application.

Aktualisiert am 30. September 2026 · MASTR Labs

Artikeltexte und technische Grafiken sind auf Englisch. Die Navigation ist in 7 Sprachen verfügbar.

Fachartikel
  1. Two separate layers
  2. What the padlock cannot tell you
  3. Where a compromise can still matter
  4. Reporting an incident precisely
  5. Konkretes Beispiel
  6. Quellen und Originale

Two separate layers

DNS translates a hostname into records used to reach a service. DNSSEC can authenticate signed DNS data through a chain of trust. TLS, used by HTTPS, authenticates the server endpoint under its certificate rules and protects the transport session. These mechanisms address different parts of a connection. A site can use HTTPS without DNSSEC; a signed DNS answer is not encrypted webpage traffic. 1 2

What the padlock cannot tell you

A valid certificate for a lookalike domain does not make it the intended wallet provider. HTTPS can securely deliver a malicious page operated by the holder of that domain. DNSSEC similarly cannot promise that the destination’s application is honest or that its code has not changed. Both protections should be understood as narrow technical assertions, not seals of investment quality.

Where a compromise can still matter

An application has additional dependencies: registrar and DNS administration, hosting, build pipeline, scripts and wallet interaction. Protecting one layer does not remove the others. For readers, carefully verified bookmarks and an independent check of a project’s official domain reduce ambiguity. For operators, documented domain ownership and tested recovery procedures belong alongside server security.

Reporting an incident precisely

Distinguish an incorrect DNS answer, a certificate problem, a compromised web application and a misleading domain registration. They have different evidence and remedies. Record the hostname, time and observed behaviour without converting every suspicious page into a claim that ‘the blockchain was hacked’. A failed certificate check should not be bypassed merely because a social-media post says the website is official.

The website has several trust layers
Erklärende Grafik. In voller Grösse öffnen. Credits ↗ A valid connection does not certify the destination’s honesty.

Konkretes Beispiel

A fraudulent site at a different spelling can obtain a valid certificate for its own domain. The browser then encrypts the connection to that fraudulent site correctly. The transport worked; the user’s intended destination was wrong. TLS validation cannot decide that intention.

Quellen und Originale

  1. RFC 4033: DNS security
  2. RFC 8446: TLS 1.3

Weiterlesen

Namen, Identität und Web-Inhalte →

MASTR

Unabhängige Recherche unterstützen

Die Untersuchungen, Originalbelege und Anleitungen hier sind frei zugänglich. Freiwillige Spenden finanzieren die Recherche mit und helfen, die MASTR-Tools weiterhin anzubieten.

Wallet öffnen