DNS — Domain Name System5 min read2 sections

DNSSEC — Securing the Domain Name System

How DNSSEC protects against DNS spoofing and cache poisoning with cryptographic signatures and chain of trust.

01

Why DNSSEC?

DNS was designed in 1983 without any security mechanisms. An attacker can forge DNS responses without the client being able to detect it.

Threats Without DNSSEC

  • DNS Cache Poisoning: An attacker injects forged records into a resolver's cache. All users of that resolver are then redirected to a fake IP.
  • DNS Spoofing: An attacker responds faster than the legitimate DNS server with a forged answer.
  • Man-in-the-Middle: An attacker on the network path modifies DNS responses in real-time.

What DNSSEC Provides

  • Authenticity: Proves the DNS response comes from the legitimate zone owner
  • Integrity: Proves the response was not modified in transit
  • Authenticated Denial: Proves that a queried record truly does not exist
⚠️ Important: DNSSEC does not provide encryption. DNS queries and responses are still visible in plain text. For encrypted DNS queries, use DNS over HTTPS (DoH) or DNS over TLS (DoT).
02

Setting Up DNSSEC

Step 1: Sign the Zone

Your DNS provider (or you, if running your own nameservers) must sign the zone with a ZSK and KSK. Most managed DNS providers (Cloudflare, Route 53, Dyn) offer this with a single click.

Step 2: Register DS Record with Registrar

The DS record must be entered at your domain registrar so it appears in the parent zone (.com, .de etc.). You typically need:

  • Key Tag: A numeric ID of the key
  • Algorithm: e.g. 13 (ECDSAP256SHA256) or 8 (RSASHA256)
  • Digest Type: 2 (SHA-256)
  • Digest: The hash value of the KSK

Step 3: Verify Validation

# DNSSEC-validated query
dig +dnssec example.com A

# Show signatures
dig example.com RRSIG

# Verify chain of trust
delv example.com A @8.8.8.8

Common Mistakes

  • Forgetting key rotation: ZSK should be rotated every 1–3 months, KSK every 1–2 years
  • Letting signatures expire: RRSIG records have an expiration date — if not renewed in time, the entire zone is considered invalid
  • DS not updated during key rollover: When the KSK is renewed, the DS at the registrar must also be updated