Why DNSSEC?
DNS was designed in 1983 without any security mechanisms. An attacker can forge DNS responses without the client being able to detect it.
Threats Without DNSSEC
- DNS Cache Poisoning: An attacker injects forged records into a resolver's cache. All users of that resolver are then redirected to a fake IP.
- DNS Spoofing: An attacker responds faster than the legitimate DNS server with a forged answer.
- Man-in-the-Middle: An attacker on the network path modifies DNS responses in real-time.
What DNSSEC Provides
- Authenticity: Proves the DNS response comes from the legitimate zone owner
- Integrity: Proves the response was not modified in transit
- Authenticated Denial: Proves that a queried record truly does not exist
Setting Up DNSSEC
Step 1: Sign the Zone
Your DNS provider (or you, if running your own nameservers) must sign the zone with a ZSK and KSK. Most managed DNS providers (Cloudflare, Route 53, Dyn) offer this with a single click.
Step 2: Register DS Record with Registrar
The DS record must be entered at your domain registrar so it appears in the parent zone (.com, .de etc.). You typically need:
- Key Tag: A numeric ID of the key
- Algorithm: e.g. 13 (ECDSAP256SHA256) or 8 (RSASHA256)
- Digest Type: 2 (SHA-256)
- Digest: The hash value of the KSK
Step 3: Verify Validation
# DNSSEC-validated query dig +dnssec example.com A # Show signatures dig example.com RRSIG # Verify chain of trust delv example.com A @8.8.8.8
Common Mistakes
- Forgetting key rotation: ZSK should be rotated every 1–3 months, KSK every 1–2 years
- Letting signatures expire: RRSIG records have an expiration date — if not renewed in time, the entire zone is considered invalid
- DS not updated during key rollover: When the KSK is renewed, the DS at the registrar must also be updated
Related articles
DNS Fundamentals — How the Internet's Phone Book Works
Understanding the Domain Name System from the ground up: resolution process, hierarchy, caching, and why DNS is critical for everything online.
ReadDNS Record Types — Complete Reference
Detailed reference of all DNS record types: A, AAAA, CNAME, MX, NS, TXT, SOA, PTR, SRV, CAA, DS, DNSKEY, NAPTR, SSHFP and more.
Read