RFC 2065:Domain Name System Security Extensions
RFC-Ref

dynamic update


Click on the red underlined text to get to the source

... resource record is signed by other than the zone private key. One is for support of dynamic update where an entity is permitted to authenticate ...
... signing requests is defined in connection with authenticating future secure dynamic update requests or the like. ...


... connection with DNS dynamic update or other new DNS commands. Zone keys always have authority ...
... be used in connection with some modes of DNS dynamic update. For number 253, the public key area is null. Values 0 and 255 are ...


... used in connection with some modes of DNS dynamic update. For number 253, the signature field will be null. Values 0 and 255 are ...
... RRs which are authenticated by a dynamic update key and not by the zone key (see Section 3.2) are not included in the AXFR ...
... authenticate future DNS secure dynamic update or other requests. ...


... NXT feature which would eliminate this possibility. But it would be more complex and might be so constraining as to make any dynamic update feature very difficult. ...



Google
Web
RFC-Ref