Introducing Verisign Informed™: A High-Assurance Solution for Validating Trust at the Speed of Modern Threats

New technology is accelerating global reliance on digital infrastructure, yet also enabling and surfacing new security threats. Among these is “stale trust,” in which critical trust decisions are made based on out-of-date validation information. Verisign Informed™ addresses this problem by enabling trust decisions to be made using current status information for any digital certificate transaction, reducing online and enterprise risk.

There are two clear trends that together present significant risks to online commerce, privacy, and security. The first is a perennial and increasing reliance on digital services, and this reliance is increasing rapidly with the growing use of AI. We see this increasing reliance in the rapid growth of transactions in the DNS infrastructure we operate. Over the 7-year period 2016-2022, the average number of daily DNS transactions Verisign processed rose by a compound annual growth rate of 9.3 percent; in the 3-year period 2023-2025, the compound rate nearly doubled to 17.3 percent. Our analyses indicate that an increasing segment of this growth is driven by rapid AI deployment.

The second trend is the growth of cyberthreat risks and attacks, which are increasing in frequency and sophistication. The velocity and volume of new zero-day attacks threaten the effectiveness of traditional defense mechanisms and practices, such as patching. Exploit time – defined as the time between a vulnerability being discovered and that vulnerability being exploited – has dropped from hundreds of days to only minutes. Breakout time – defined as the time it takes for an attacker to penetrate beyond a compromised system to other parts of a network – has dropped from days to minutes. AI-created deepfakes fundamentally erode users’ ability to trust what they see, enabling online and other fraud. And, as we’re learning, it must be assumed that with AI, all vulnerabilities will be identified and followed by near-immediate AI-enabled attack chains.

Digital certificate trust foundations – operationally hardened and enhanced to meet the modern threat landscape – can significantly mitigate many of these new risks. Public-key Infrastructure, or PKI, has long been the bedrock for powering security and privacy protections in network protocols, digital credentials, secure documents, images, embedded devices, and much more. It plays a key role in numerous standards and has been well tested. As a result, its supporting features, tools, and extended protocol support have positioned it at the heart of many of our most effective security solutions. Containing and limiting agent behavior, a growing concern, already recognizes the importance of PKI trust tools for verifying, authorizing, and restricting access. With much of this activity occurring machine-to-machine, high-performance and globally available trust services become essential.

Use of PKI to minimize risk is cited frequently in NIST’s Zero Trust (ZT) architecture, which offers risk-reduction principles based on a “never trust, always verify” approach. Understanding trust at the time of transactions – the purpose for which Verisign Informed was designed – is critical in today’s threat landscape. Private PKI, object security and the emergence of agentic AI underline why current trust status information is of paramount importance. An organization’s “mean time to adapt” once a compromise has been detected hinges on their ability to signal that to relying parties, and thereby substantially reduce the risk of further damage.

PKI’s importance also makes it an implicit target for attackers, as un-remediated compromise of credentials can enable systematic and enduring compromise of dependent systems, both within and outside of the observation space of the target. Verisign Informed provides current security status to clients and other relying parties and is also a foundation for providing richer context via the extensible architecture of the Online Certificate Status Protocol (OCSP). This allows security practitioners to quantifiably minimize their “vulnerability windows,” – the periods when compromised credentials can be exploited.

Although these issues are well understood by security professionals, until now, there has been no clear solution. In a March 2026 Forrester Consulting study of IT leaders commissioned by Verisign, 97 percent said that extended digital certificate validation gaps are a risk when making trust decisions in light of identity-based threats, and that reducing digital certificate validation gaps in private PKI is becoming increasingly critical as cyberthreats and agentic AI accelerate the speed and scale of identity-based threats.

These same individuals saw numerous benefits to closing these windows of vulnerability; notably, 84 percent identifying closing validation gaps as key to a stronger Zero Trust posture for their organizations. Rapidly closing these windows is necessary so that compromised credential remediation can occur.

Microsegmentation, the Zero Trust-specified practice of treating networks as isolated segments, each requiring validated credentials authorizing access for clients and workloads, further accelerates the number of validations performed by policy enforcement points.

Verisign Informed delivers highly available, current certificate status information, enabling “at time of use” verification of a certificate’s validity and the trust it underlies. In existing solutions, validity information can be hours – or days – out of date, creating attack windows where a relying party trusts a credential that has already been known compromised and even revoked, but the current status hasn’t been effectively conveyed to relying party applications or services.

Validation at time of trust decision is fundamental for public and private transactions, and critical for establishing trust in current and new uses of the internet. Alongside the introduction of Verisign Informed, Verisign is actively engaged in helping create standards for solving new challenges with trust in the internet. The emerging challenge of AI-created deepfakes is being combatted by the Coalition for Content Provenance and Authenticity (C2PA) and the Creator Assertions Working Group (CAWG), of which Verisign is a participating member, by incorporating and leveraging PKI. In Agentic discovery, capability assessment, trust establishment and secure communications, we have identified certificate-based solutions, including Domain Name System Security Extensions (DNSSEC) and DNS-based Authentication of Named Entities (DANE), and are proposing new certificate validated DNS record types to facilitate optimal Agentic use of the DNS, alongside an evaluation framework for assessment of potential agent discovery approaches.

Verisign Informed builds on Verisign’s significant experience in both high-assurance critical infrastructure and Public-key Infrastructure. Verisign’s two-pronged history is one of deep experience in operating high-assurance critical DNS infrastructure, and pioneering PKI at global scale. We are now leveraging the synergies between these two critical technologies to meet an emergent security challenge.

Verisign Informed is powered and backed by Verisign’s high-assurance infrastructure: We define “high assurance” as a service that can deliver the highest levels of availability, accuracy, and performance, all at global scale. Our secure and resilient global DNS infrastructure has provided over 29 years of uninterrupted, 100% service level availability of our COM/NET resolution services. As AI automates more business processes on which services and revenues depend, reliability takes on new significance.

Today, we are processing more than 746 billion authoritative DNS transactions on average per day (and growing), which equates to approximately 8.6 million transactions per second, every second of every day. We provide cryptographically protected responses globally, with the vast majority answered within milliseconds. Through a variety of methods, we have and will continue to maintain multiple orders of magnitude in reserve capacity. And we will continue to maintain the security and stability of our cryptographic protections for the long term, including through our pioneering leadership in preparing DNSSEC for the post-quantum era.

Our purpose-built infrastructure has continually evolved over decades to serve one purpose: delivering services worldwide with speed, accuracy, and availability. Put simply, we believe that Verisign Informed, operating in our high assurance infrastructure, will significantly strengthen one of today’s most widely used and critically important tools of trust.

Finally, Verisign has applied for the .pki gTLD in the next round of ICANN’s new gTLD program. We see .pki as a potentially useful gTLD within PKI usage scenarios.

Today marks the opening of the limited beta for Verisign Informed. Verisign Informed was developed, tested, and enabled in our infrastructure during late 2025 and early 2026. The initial development and operational testing processes are complete. With the current OCSP standard providing a means for specifying the validation service provider of choice, the provisioning, activation, and transaction flow are nearly identical to domain registration and resolution, delivering the full performance and availability benefits of our high-assurance infrastructure at global scale.

To learn more about Verisign Informed, visit https://www.verisigninformed.com.
To access the full set of insights gained in the Forrester study, visit the Forrester Opportunity Snapshot.

Accompanying this blog and in additional writings in the coming weeks we will share more details about Verisign Informed, analyses of the threats it addresses, and the importance of high-assurance validation in a series of blogs. Our plan is to make Verisign Informed generally available in the first half of 2027. Verisign Informed is designed to be enabled by PKI services providers, including Registrars who offer enterprise PKI services, or directly by end customers that manage their own PKI, by leveraging the features already built into the OCSP standard.

Verisign Informed, operating within our High-Assurance infrastructure, can provide a stronger foundation of high-security tools on which new services can be deployed with the speed, trust, and reliability required in today’s world of accelerating risks and threats.

Digital blue and purple pathways intersect and overlap.

Proposed New DNS Resource Record Types for AI Agent Discovery

This blog post is based on a paper titled “Efficient and Secure Discovery for AI Agents: The Case for DNS,” authored by Ramachandra Rao Seethiraju, Sameer Thakar, Karthik Shyamsunder, and Eric Osterweil. This blog was co-authored by all four authors.

For more than three decades, domain names have served as a foundational identity layer for internet applications. Initially used to identify early network services such as TELNET, FTP, and email, they later became essential to web browsing and a growing range of online services. Their enduring value lies in their ability to provide unique, stable, neutral, and widely recognized identifiers across changing technologies and use cases.

(more…)
Close-up of a circuit board with glowing blue and orange pathways.

The 2024-2026 Root Zone KSK Rollover: Updates and Observations

This blog post is co-authored by Duane Wessels (Verisign) and Roy Arends (ICANN).

Roughly a year and a half ago, Verisign and the Internet Corporation for Assigned Names and Numbers (ICANN) began the important, multi-year process of updating the cryptographic key that secures the authoritative Domain Name System (DNS) root zone. This work has been largely invisible to the public, but vital to the security of many everyday online activities.

(more…)

Domain Name Industry Brief Quarterly Report: DNIB.com Announces 401.6 Million Domain Name Registrations in the Second Quarter of 2026

Today, the latest issue of The Domain Name Industry Brief Quarterly Report was released by DNIB.com, showing the second quarter of 2026 closed with 401.6 million domain name registrations across all top-level domains (TLDs), an increase of 9.1 million domain name registrations, or 2.3% compared to the first quarter of 2026. Domain name registrations increased by 29.9 million, or 8.1%, year over year.

(more…)

Domain Name Industry Brief Quarterly Report: DNIB.com Announces 392.5 Million Domain Name Registrations in the First Quarter of 2026

Today, the latest issue of The Domain Name Industry Brief Quarterly Report was released by DNIB.com, showing the first quarter of 2026 closed with 392.5 million domain name registrations across all top-level domains (TLDs), an increase of 5.6 million domain name registrations, or 1.4% compared to the fourth quarter of 2025. Domain name registrations increased by 24.1 million, or 6.5%, year over year.

(more…)

Domain Name Industry Brief Quarterly Report: DNIB.com Announces 386.9 Million Domain Name Registrations in the Fourth Quarter of 2025

Today, the latest issue of The Domain Name Industry Brief Quarterly Report was released by DNIB.com, showing the fourth quarter of 2025 closed with 386.9 million domain name registrations across all top-level domains (TLDs), an increase of 8.4 million domain name registrations, or 2.2% compared to the third quarter of 2025. Domain name registrations increased by 22.7 million, or 6.2%, year over year.

(more…)
Verisign Logo

Data Refutes Short Sellers’ Flawed Reports About Negative Impacts on .Com Domain Name Base

In October, stock “short sellers” – investors who bet on the likelihood that stocks will decline in value – published misleading and inaccurate reports about “parked” .com domain names and how those domain names would be affected by ongoing changes to Google AdSense. We believe that the short sellers hoped to profit by declines in our stock price due to the false information they published. While we explained the inaccuracy of these reports at the time of their publication based on historical data, we now have a growing body of publicly available data that empirically refutes the short sellers’ predictions.

(more…)

Preparing DNSSEC for the Post-Quantum Era

The Domain Name System Security Extensions (DNSSEC) help protect the integrity of DNS data, supporting both online navigation and other uses of domain names as identifiers in applications. In the time since DNSSEC was first introduced in 2005, both the RSA algorithm and elliptic curve cryptography have served as the primary signature algorithms for DNSSEC. But with the potential of large-scale quantum computing on the horizon, there may soon come a time when those algorithms no longer suffice.

(more…)

Domain Name Industry Brief Quarterly Report: DNIB.Com Announces 378.5 Million Domain Name Registrations in the Third Quarter Of 2025

Today, the latest issue of The Domain Name Industry Brief Quarterly Report was released by DNIB.com, showing the third quarter of 2025 closed with 378.5 million domain name registrations across all top-level domains (TLDs), an increase of 6.8 million domain name registrations, or 1.8% compared to the second quarter of 2025. Domain name registrations increased by 16.2 million, or 4.5%, year over year.

(more…)

Domain Name Industry Brief Quarterly Report: DNIB.com Announces 371.7 Million Domain Name Registrations in the Second Quarter of 2025

Today, the latest issue of The Domain Name Industry Brief Quarterly Report was released by DNIB.com, showing the second quarter of 2025 closed with 371.7 million domain name registrations across all top-level domains (TLDs), an increase of 3.3 million domain name registrations, or 0.9% compared to the first quarter of 2025. Domain name registrations increased by 9.3 million, or 2.6%, year over year.

(more…)