Resources

What is DNSSEC?

DNSSEC signs the records in a zone so a resolver can prove the answer it received is the one you published.

Plain DNS answers can be forged in transit. DNSSEC adds signatures over the record sets, and a chain of trust from the root down to your zone.

The chain closes at the registrar: a DS record there points at the key in your zone. Signing without publishing the DS proves nothing.

Key rollovers and signature lifetimes have to be handled, which is why DNSSEC is a service, not a checkbox.

At CTPFDNS signing is being rolled out: a domain is signed once its move to our nameservers is complete.

All resources