NIS2: The DNS an Auditor Can Query

Blog 3 min read

Article 21 does not name DMARC. An auditor still queries the live record. p=none is not evidence.

NIS2 Article 21 does not contain the line “install DMARC”. It asks for hygiene, cryptography, detection and supply-chain control. An auditor reads the record visible from outside, not the sentence in a policy PDF. If the record is missing, the intention is not evidence.

Whether your shop is in scope, and what a hosting contract should say after Bulgaria’s 17 February 2026 entry into force, is a separate article. This one is only the DNS layer someone can query.

Five things visible from outside

  • DMARC: p=none collects reports. It does not stop forgery. An enforcing policy is p=quarantine or p=reject, plus an rua address someone reads. An unread report address is not detection.
  • DKIM: The signature is the concrete record people map to the cryptography expectation. The key sits in DNS. The message carries it.
  • DNSSEC: If the zone is unsigned, you have no evidence at this layer against cache poisoning. Test the chain against the nameserver before you turn it on. A broken chain takes the site down.
  • CAA: It limits which authority may issue a certificate. Leaving it open does not stop a CA you do not use from issuing for your name.
  • SPF: Third-party senders that arrive as includes hit permerror after the tenth lookup. A broken SPF drops the sentence “we have email hygiene”.

What does not count

A PDF line that says “DNS is secure” does not replace the record dig returns. A hosting contract can describe backups and location. It does not write DMARC on your domain. If the zone is in your account, the record is your job. EuroVDC nameservers ns1.eurovdc.eu and ns2.eurovdc.eu only publish the line you entered.

The shape of a record is not evidence. The live query is

An auditor does not want a sample paragraph. They want the record that resolves now. The shape looks like this. Pasting it does not put you in scope:

  • DMARC: v=DMARC1; p=reject; rua=mailto:dmarc@company.com. p=none is the same line with nothing enforced.
  • CAA: 0 issue "letsencrypt.org". Write that only if that is the authority you use, so another one does not issue for your name.
  • DNSSEC: the signature lives in the zone, the DS lives at the registrar. If one is missing, the site goes down “because security was turned on”. Test first, then publish the DS.

EuroVDC nameservers publish the line you entered. Pasting it into a contract does not make the query pass.

Frequently asked questions

Does a small site have to do this?

Scope depends on turnover and sector. The other article separates that. Even outside scope, p=none does not stop forged mail. The record is cheap. The excuse is not.

Is MTA-STS required?

Article 21 does not name it. If you do not want inbound mail to fall back to clear text, you publish both the TXT and /.well-known/mta-sts.txt. The TXT alone is not enough.

Should I enable DNSSEC today?

Yes, if the chain and the nameserver are ready together. A half signature takes the site down “for security”. Test first, then publish the DS.

Will the auditor log into the EuroVDC panel?

What they usually want is the record anyone can query, not the panel. You publish that record.

nis2 dnssec dmarc caa dns

EuroVDC

Host Your Website with Confidence

NVMe SSD storage · Free SSL · cPanel included

View Web Hosting Plans

Did you find this content useful?

– People found it useful

Share on Social Media

NIS2: The DNS an Auditor Can Query