How to enable DNSSEC without breaking your domain

DNSSEC adds digital signatures to your DNS records so resolvers can detect forged answers, which protects against spoofing and cache poisoning. It works as a chain of trust. Your zone publishes a public key (DNSKEY) and signs its records (RRSIG), and the parent zone publishes a fingerprint of that key, called a DS record.

Why it matters

A domain with DNSSEC enabled is harder to hijack with forged answers. The risk is the other direction: if the DS record at the parent does not match the keys in your zone, validating resolvers treat every answer as forged and your domain stops resolving for them.

How to enable it

  1. Turn on signing at your DNS provider. Most providers do this with one setting, and choose sensible algorithms for you. ECDSAP256SHA256 (algorithm 13) is a good choice if you must pick.
  2. Copy the DS record details the provider shows you: key tag, algorithm, digest type and digest.
  3. Add the DS record at your registrar.
  4. Run DNSLint. It looks for the DS record at the parent zone.

Do it in that order. Publishing a DS record before the zone is signed breaks resolution for validating resolvers.

Avoiding outages

Check your domain