Domains and DNS
DNSSEC
DNSSEC protects DNS answer authenticity once the registrar publishes the DS.
#Overview
DNSSEC protects DNS answer authenticity once the registrar publishes the DS.
#Establish the trust chain
Enabling DNSSEC prepares signing and returns DS data to publish at the registrar. Protection is complete only when the parent DNS carries the matching DS and the check validates the chain.
A wrong DS value can make the domain unresolvable for validating resolvers. Keep the active setup until the parent has been checked and plan changes with registrar access available.
#Enable DNSSEC
Enable DNSSEC for the zone.
Copy the displayed algorithm, digest, and DS fields exactly.
Publish the DS at the registrar.
Run the check and wait for a valid chain before closing the change.