---
id: "trust-anchor"
kind: "glossary-term"
title: "信任锚"
language: "zh-Hans"
category: "DNS与技术基础"
updated: "2026-10-10T12:00:00Z"
canonical: "https://tldlog.com/zh/cihui/xinren-mao/"
translations:
  en: "https://tldlog.com/glossary/trust-anchor/"
  es: "https://tldlog.com/es/glosario/anclaje-confianza/"
  de: "https://tldlog.com/de/glossar/vertrauensanker/"
  fr: "https://tldlog.com/fr/glossaire/ancre-confiance/"
  it: "https://tldlog.com/it/glossario/trust-anchor/"
  pt-BR: "https://tldlog.com/pt/glossario/ancora-confianca/"
  ru: "https://tldlog.com/ru/glossariy/yakor-doveriya/"
---

# 信任锚

执行DNSSEC验证的解析器被预先设置为直接信任、无须其他来源证明的公钥。实际上，这就是由IANA公布的根区密钥。每一次DNSSEC验证都以这把密钥为终点，因此解析器必须持有当前有效的密钥。

## 相关术语

- [KSK](https://tldlog.com/zh/cihui/ksk/)
- [信任链](https://tldlog.com/zh/cihui/xinren-lian/)
- [DNSSEC验证](https://tldlog.com/zh/cihui/dnssec-yanzheng/)
- [密钥轮转](https://tldlog.com/zh/cihui/miyao-lunzhuan/)
- [根区](https://tldlog.com/zh/cihui/genqu/)
