DNSSEC (2/2) DS RR: Delegation Signer KSK's hash digest stored in the parent zone for secure delegation signed with parent's ZSK Verifying the sign Get RRSIG RR for a response Verify the signature using the DNSKEY RR Ensure the validity of DNSKEY by upper zone's DS RR ...constructing "a chain of trust" to the root zone get the root zone's DNSKEY in some out-of-band method