DNS authenticity

Understand what DNSSEC protects

DNSSEC adds digital signatures to DNS data so validating resolvers can detect forged or altered answers. It authenticates DNS responses; it does not encrypt traffic or replace HTTPS.

Signed answersDetect unauthorised changes.

Chain of trustRegistry DS links the keys.

Coordinate changesWrong keys can break DNS.

Protection

DNSSEC helps resolvers reject forged DNS data

The authoritative DNS provider signs the zone. A validating resolver checks those signatures and the parent chain of trust before accepting an answer, reducing the risk of certain cache-poisoning and response-manipulation attacks.

What it does not do

DNSSEC does not encrypt DNS or secure the website connection

Use HTTPS and a valid SSL certificate to encrypt browser traffic. Use secure mail settings for email and strong account security to protect changes. DNSSEC complements these controls rather than replacing them.

UKC availability

DNSSEC Setup is available for selected Active domains

The authenticated account owner can use Domains > Manage Domain > DNSSEC Setup for Nominet-managed domains in the .UK namespace and Domainbox-managed .com, .net and .org domains. Other registrar and extension combinations do not currently show the tab.

Safe operation

The DNS provider must supply the exact DS values

The DNS provider creates and maintains the keys; UKC publishes the supplied DS record through the supported registrar connection. Do not create, guess or copy values from another domain. A wrong or stale DS record can make websites and email unreachable through validating networks.

Coordinate DS records whenever signing keys, nameservers or DNS provider change. During a key rollover, follow the provider's sequence because old and new records may both be required temporarily.

Need step-by-step instructions?

Our detailed guide explains the four DS fields, Client Area workflow, key rollovers, provider moves and safe removal.

Read the DNSSEC guide

Was this answer helpful?

« Back