cdn.pizzaDocumentation

Domains and DNS

DNSSEC

DNSSEC protects DNS answer authenticity once the registrar publishes the DS.

#Overview

DNSSEC protects DNS answer authenticity once the registrar publishes the DS.

#Establish the trust chain

Enabling DNSSEC prepares signing and returns DS data to publish at the registrar. Protection is complete only when the parent DNS carries the matching DS and the check validates the chain.

A wrong DS value can make the domain unresolvable for validating resolvers. Keep the active setup until the parent has been checked and plan changes with registrar access available.

#Enable DNSSEC

  1. Enable DNSSEC for the zone.

  2. Copy the displayed algorithm, digest, and DS fields exactly.

  3. Publish the DS at the registrar.

  4. Run the check and wait for a valid chain before closing the change.

Customer documentationReference generated from published interfaces