DNSSEC (Domains)

DNSSEC, or Domain Name System Security Extensions, is a security feature that helps protect your domain’s DNS information from tampering. It adds a layer of verification to DNS responses so that devices and services can confirm that the DNS data they receive is authentic and has not been altered in transit.

This is important because standard DNS was not originally designed with strong built-in verification. Without DNSSEC, attackers may be able to interfere with DNS lookups in some situations, potentially redirecting visitors to the wrong website or affecting other domain-related services.

If you manage a domain name, DNSSEC is most relevant when you want to improve DNS trust and reduce the risk of forged DNS responses. It is commonly used with domains that host websites, email services or other internet-facing systems where DNS integrity matters.

What DNSSEC is

DNSSEC is a set of extensions to the Domain Name System. It does not encrypt DNS records, and it does not hide them from public view. Instead, it uses digital signatures to help confirm that DNS records came from the correct source and were not modified.

When DNSSEC is enabled and configured correctly, DNS resolvers that support validation can check the signatures attached to DNS data. If the signatures are valid, the resolver can trust that the DNS response is authentic. If the validation fails, the resolver may reject the response.

This helps protect against certain attacks such as DNS spoofing or cache poisoning, where false DNS information is provided in an attempt to redirect traffic.

How DNSSEC works

DNSSEC works by adding cryptographic signatures to DNS zone data.

The basic idea is:

1. The DNS zone owner generates cryptographic keys.

2. The zone signs its DNS records using a private key.

3. Public key information is published in the DNS zone.

4. A DS record, short for Delegation Signer record, is published at the parent zone level, usually through the domain registrar.

5. Validating resolvers use this chain of trust to check whether the DNS response is genuine.

If the chain of trust is complete and valid, the resolver accepts the response. If the chain is broken or the signatures do not match, the resolver may treat the DNS response as invalid.

In practice, this means DNSSEC depends on both the DNS hosting provider and the domain registrar being configured correctly.

Key DNSSEC terms

* DNSSEC: A set of DNS security extensions that uses digital signatures to validate DNS data.

* Zone signing: The process of digitally signing a DNS zone.

* DNSKEY record: A DNS record that publishes the public signing key for the zone.

* DS record: A record published in the parent zone that links the domain to its DNSSEC key information.

* Chain of trust: The validation path from the parent zone to the signed child zone.

* Validating resolver: A DNS resolver that checks DNSSEC signatures before accepting DNS data.

Why DNSSEC matters

DNSSEC helps improve trust in DNS responses. This can be important for:

* Business websites that want stronger DNS security.

* Services that depend on accurate DNS responses, such as email delivery.

* Organisations that want to reduce the risk of redirection caused by forged DNS replies.

* Domains used with other security-sensitive services.

DNSSEC does not replace SSL certificates, HTTPS, firewalls or other security controls. Instead, it protects a different part of the service chain. HTTPS helps secure the connection between a visitor and a website, while DNSSEC helps validate the DNS information that tells the visitor where to connect.

Before you enable DNSSEC

Before enabling DNSSEC for a domain, make sure you understand who manages:

* The domain registration.

* The authoritative DNS hosting.

* Any existing DNS changes planned for the domain.

You should also confirm whether your DNS provider supports DNSSEC signing and whether your registrar supports DS record management for the domain extension you are using.

If DNSSEC is configured incorrectly, your domain may stop resolving properly for users whose resolvers validate DNSSEC. Because of this, DNSSEC changes should be planned carefully.

General process for enabling DNSSEC

The exact steps depend on your DNS provider and domain registrar, but the general process is usually:

1. Confirm that your authoritative DNS provider supports DNSSEC.

2. Enable DNSSEC signing for the DNS zone with that provider.

3. Obtain the DS record details or DNSSEC key details from the DNS provider.

4. Log in to the domain registrar or domain management portal.

5. Add the DS record to the domain at the registrar level.

6. Save the changes and allow time for DNS updates to take effect.

7. Test DNSSEC using a trusted DNSSEC validation tool.

Some providers automate part of this process, while others require manual entry of DS record values.

Important notes and best practices

* Only enable DNSSEC if you know which provider hosts the domain’s authoritative DNS zone.

* Do not add a DS record unless the DNS zone is already correctly signed.

* If you move DNS hosting to another provider, review DNSSEC settings before and after the move.

* If you disable DNSSEC signing at the DNS host, remove the DS record from the registrar to avoid validation failures.

* Keep a record of the current DNS provider, DNSSEC status and any related changes made to the domain.

* Make DNS changes during a period where you can monitor the domain for issues.

Common problems

Incorrect DNSSEC configuration can cause a domain to become unavailable for some users. Common causes include:

* A DS record exists at the registrar, but the DNS zone is not signed correctly.

* The domain has moved to a new DNS provider, but the old DS record is still published.

* DNSSEC keys were changed or rolled over incorrectly.

* The registrar or DNS provider settings do not match.

Because DNSSEC failures can affect website and email access, changes should be verified after configuration.

Troubleshooting

The website or email stopped working after enabling DNSSEC

This may indicate a broken DNSSEC chain of trust or invalid signatures. Check whether the DNS zone is signed correctly and whether the DS record at the registrar matches the active DNSSEC key information from the DNS provider.

I can see DNS records, but some users cannot access the domain

Some DNS resolvers validate DNSSEC and others may not. If only some users are affected, DNSSEC validation failure is a possible cause. Test the domain with a DNSSEC validation tool and review the signer and DS record configuration.

I changed DNS providers and the domain stopped resolving

If DNSSEC was previously enabled, the old DS record may still be published at the registrar. Confirm whether the new DNS provider supports DNSSEC and whether the registrar is using the correct DS record for the current DNS host.

Frequently asked questions

Does DNSSEC encrypt my DNS records?

No. DNSSEC does not encrypt DNS data. It adds digital signatures to help validate authenticity.

Does DNSSEC replace SSL or HTTPS?

No. DNSSEC and HTTPS do different jobs. DNSSEC helps protect DNS lookups, while HTTPS secures website traffic between the visitor and the web server.

Do all users benefit from DNSSEC?

DNSSEC protection depends in part on whether the user’s DNS resolver performs DNSSEC validation. Many modern resolvers do, but support can vary.

Can DNSSEC break a domain if it is configured incorrectly?

Yes. Incorrect DNSSEC configuration can cause validation failures, which may prevent the domain from resolving for some users.

Do I need DNSSEC for every domain?

Not every domain uses DNSSEC, but it can provide an additional layer of DNS security where supported and properly managed.

Related Articles

* Domain Names Explained

* What is DNS?

* Nameservers

* DNS Records

* WHOIS

* Domain Troubleshooting

If you require further assistance, please contact Apexhost Support at support@apexhost.com.au.

  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

Domain Names Explained (Domains)

Introduction A domain name is the human-readable address that people type into a web browser...

Registering Domains (Domains)

Registering a domain name is one of the first steps in creating a website, setting up business...

Renewing Domains (Domains)

How to Renew a Domain Name Introduction A domain name is the address customers use to...

Domain Transfers (Domains)

Introduction A domain transfer moves the registration of a domain name from one registrar to...

EPP CODES (Domains)

EPP Codes (Domains) An EPP code is a domain transfer authorisation code used to approve the...