ISNIC has now finished the first stage in implementing DNSSEC for the .is TLD, by signing the .is zone and having the corresponding DS records published in the root zone by IANA. Records in the is zone can now be authenticated by properly configured DNS resolvers that support DNSSEC.
The next step in the implementation is to allow domain holders to publish their DS records in the .is zone so their signed zone can be authenticated by the chain of trust to the root zone. Then domain holders can be assured that properly configured resolvers can and will authenticate responses from their domain servers and will disregard attempts from attackers to disrupt or poison the DNS system.
Read Further