How to enable DNSSEC without breaking your domain
DNSSEC adds digital signatures to your DNS records so resolvers can detect forged answers, which protects against spoofing and cache poisoning. It works as a chain of trust. Your zone publishes a public key (DNSKEY) and signs its records (RRSIG), and the parent zone publishes a fingerprint of that key, called a DS record.
Why it matters
A domain with DNSSEC enabled is harder to hijack with forged answers. The risk is the other direction: if the DS record at the parent does not match the keys in your zone, validating resolvers treat every answer as forged and your domain stops resolving for them.
How to enable it
- Turn on signing at your DNS provider. Most providers do this with one setting, and choose sensible algorithms for you. ECDSAP256SHA256 (algorithm 13) is a good choice if you must pick.
- Copy the DS record details the provider shows you: key tag, algorithm, digest type and digest.
- Add the DS record at your registrar.
- Run DNSLint. It looks for the DS record at the parent zone.
Do it in that order. Publishing a DS record before the zone is signed breaks resolution for validating resolvers.
Avoiding outages
- Moving DNS providers: remove the DS record at the registrar and wait for its TTL to pass before switching nameservers. Then enable DNSSEC at the new provider and add the new DS record.
- Changing keys: follow your provider’s key rollover process, rather than editing DS records by hand.
- Turning it off: remove the DS record first, wait out the TTL, and only then disable signing.