---
id: "chain-of-trust"
kind: "glossary-term"
title: "chain of trust"
language: "en"
category: "DNS and technical foundations"
updated: "2026-10-04T14:01:23Z"
canonical: "https://tldlog.com/glossary/chain-of-trust/"
translations:
  es: "https://tldlog.com/es/glosario/cadena-confianza/"
  de: "https://tldlog.com/de/glossar/vertrauenskette/"
  fr: "https://tldlog.com/fr/glossaire/chaine-confiance/"
  it: "https://tldlog.com/it/glossario/catena-fiducia/"
  pt-BR: "https://tldlog.com/pt/glossario/cadeia-confianca/"
  ru: "https://tldlog.com/ru/glossariy/tsepochka-doveriya/"
  zh-Hans: "https://tldlog.com/zh/cihui/xinren-lian/"
---

# chain of trust

The linked series of DNSSEC signatures that runs from the root zone down to a domain. Each parent zone holds a DS record that vouches for the child zone's key. If one link is missing or wrong, resolvers that check signatures treat the domain's answers as invalid.

## related terms

- [DNSSEC](https://tldlog.com/glossary/dnssec/)
- [DS record](https://tldlog.com/glossary/ds-record/)
- [DNSKEY record](https://tldlog.com/glossary/dnskey-record/)
- [trust anchor](https://tldlog.com/glossary/trust-anchor/)
- [DNSSEC validation](https://tldlog.com/glossary/dnssec-validation/)
