RCS and DNS: The NAPTR Record Raises Concerns Among Cybersecurity Experts
In recent months, RCS (Rich Communication Services) has been gaining traction as a more secure alternative to traditional SMS messaging. With updates to iOS and Android, RCS is becoming increasingly popular, offering end-to-end encryption and digital signatures for added security. However, the use of NAPTR records in DNS queries has raised concerns among cybersecurity experts.
NAPTR records are used to rewrite resource records using regular expressions, which can be a recipe for disaster if not implemented correctly. However, in this case, it appears that the NAPTR records are being used for RCS messaging, allowing URIs to be returned instead of just IP addresses or hostnames.
The use of SIP (Session Initiation Protocol) over TLS with TCP as the transport protocol is also noteworthy. This is a secure way to establish connections and transport messages, which is in line with the more modern and secure approach of RCS compared to traditional SMS.
As Johannes Ullrich from SANS ISC points out, the regular expression used in these NAPTR records is empty, which seems to be the norm for this use case. However, the fact that these records are being used at all has raised concerns among cybersecurity experts.
The increased visibility of NAPTR records in DNS traffic may indicate a growing trend towards using more secure communication protocols like RCS. While this is a positive development, it also highlights the need for greater awareness and understanding of these new technologies and their potential implications for cybersecurity.
Furthermore, as Ullrich notes, the use of regular expressions to rewrite resource records can be a concern if not implemented correctly. This has been highlighted in recent years with the rise of DNS-based attacks, such as DNS tunneling and DNS rebinding.
As we move forward with the adoption of more secure communication protocols like RCS, it is essential that cybersecurity experts remain vigilant and monitor the use of new technologies to prevent potential vulnerabilities from being exploited.
For users, this means being aware of the security implications of using RCS and ensuring that their devices are up-to-date with the latest security patches. It also highlights the importance of understanding how DNS works and the potential risks associated with it.
In conclusion, while the use of NAPTR records in DNS queries for RCS messaging is a positive development, it also raises concerns about the need for greater awareness and understanding of these new technologies. As we continue to move towards more secure communication protocols, cybersecurity experts must remain vigilant to prevent potential vulnerabilities from being exploited.
Source: SANS ISC — 2026-07-06