What is DNSSEC?

How DNSSEC signs DNS records so answers can’t be forged, how the chain of trust works, and why a broken DNSSEC setup makes a domain disappear.

ExplainerAdvanced2 min readUpdated

DNSSEC (DNS Security Extensions) adds cryptographic signatures to DNS records. A validating resolver can confirm that an answer really came from the domain’s authoritative nameservers and wasn’t altered on the way.

The problem it solves

Ordinary DNS answers aren’t signed. In certain attacks, a resolver can be tricked into caching a forged answer that sends visitors to the wrong server. DNSSEC makes forged answers detectable.

The chain of trust

  1. The domain’s nameservers sign its records with a key.
  2. A fingerprint of that key — the DS record — is lodged with the registry through your registrar.
  3. The registry’s own records are signed, and so on up to the DNS root.

A validating resolver follows the chain from the root down.

The danger: a broken chain

If the DS record at the registrar doesn’t match the keys on the nameservers, validating resolvers treat every answer as forged and refuse to resolve the domain. This most often happens when a domain with DNSSEC switches nameservers but the old DS record is left at the registrar.

The symptom: the domain works on some networks and not at all on others, with SERVFAIL errors.

Before changing nameservers

If DNSSEC is enabled at your current DNS provider, turn it off and remove the DS record at your registrar first, wait a day, then switch nameservers. Turning it back on is a separate step once the move is complete.

To see if a domain has a DS record:

dig yourdomain.co.uk DS +short

Any output means DNSSEC is active at the registry level.

Popular

Tip: press / to search from any pageSee all results