---
id: "rrsig"
kind: "glossary-term"
title: "RRSIG"
language: "en"
category: "DNS and technical foundations"
updated: "2026-10-04T14:01:23Z"
canonical: "https://tldlog.com/glossary/rrsig/"
translations:
  es: "https://tldlog.com/es/glosario/rrsig/"
  de: "https://tldlog.com/de/glossar/rrsig/"
  fr: "https://tldlog.com/fr/glossaire/rrsig/"
  it: "https://tldlog.com/it/glossario/rrsig/"
  pt-BR: "https://tldlog.com/pt/glossario/rrsig/"
  ru: "https://tldlog.com/ru/glossariy/rrsig/"
  zh-Hans: "https://tldlog.com/zh/cihui/rrsig/"
---

# RRSIG

Resource Record Signature

The DNS record that carries a DNSSEC digital signature. Each set of records in a signed zone has at least one, made with the zone's private key. Signatures have an expiry date, so they must be renewed regularly. Expired signatures are a common cause of DNSSEC outages.

## related terms

- [DNSSEC](https://tldlog.com/glossary/dnssec/)
- [DNSKEY record](https://tldlog.com/glossary/dnskey-record/)
- [zone signing](https://tldlog.com/glossary/zone-signing/)
- [ZSK](https://tldlog.com/glossary/zsk/)
- [DNSSEC validation](https://tldlog.com/glossary/dnssec-validation/)
