DNS authenticity
DNSSEC adds digital signatures to DNS data so validating resolvers can detect forged or altered answers. It authenticates DNS responses; it does not encrypt traffic or replace HTTPS.
Signed answersDetect unauthorised changes.
Chain of trustRegistry DS links the keys.
Coordinate changesWrong keys can break DNS.
Protection
The authoritative DNS provider signs the zone. A validating resolver checks those signatures and the parent chain of trust before accepting an answer, reducing the risk of certain cache-poisoning and response-manipulation attacks.
What it does not do
Use HTTPS and a valid SSL certificate to encrypt browser traffic. Use secure mail settings for email and strong account security to protect changes. DNSSEC complements these controls rather than replacing them.
UKC availability
The authenticated account owner can use Domains > Manage Domain > DNSSEC Setup for Nominet-managed domains in the .UK namespace and Domainbox-managed .com, .net and .org domains. Other registrar and extension combinations do not currently show the tab.
Safe operation
The DNS provider creates and maintains the keys; UKC publishes the supplied DS record through the supported registrar connection. Do not create, guess or copy values from another domain. A wrong or stale DS record can make websites and email unreachable through validating networks.
Coordinate DS records whenever signing keys, nameservers or DNS provider change. During a key rollover, follow the provider's sequence because old and new records may both be required temporarily.
Our detailed guide explains the four DS fields, Client Area workflow, key rollovers, provider moves and safe removal.
Read the DNSSEC guideArticle feedback