DNSSEC Not Configured

Your domain is not protected by DNSSEC. This makes your domain vulnerable to DNS spoofing and cache poisoning attacks.

What is DNSSEC?
DNSSEC adds cryptographic signatures to DNS records, allowing resolvers to verify that DNS responses are authentic and haven't been tampered with during transit.
Why is it important?
DNSSEC protects against DNS cache poisoning, man-in-the-middle attacks, and DNS hijacking, ensuring users reach the correct destination when accessing your domain.
Impact
Without DNSSEC, attackers can redirect your domain's traffic to malicious servers, steal credentials, distribute malware, or damage your brand reputation.

Current Configuration

DNSSEC Record Types

How DNSSEC Works

Zone Signing
Your DNS zone is signed with a private key (ZSK - Zone Signing Key), creating RRSIG records that accompany each DNS record.
Key Publication
The public key (DNSKEY) is published in your zone, allowing resolvers to verify the signatures. A Key Signing Key (KSK) signs the DNSKEY record.
Chain of Trust
A DS record is created from your KSK and published at your registrar, creating a secure chain from the root DNS to your domain.
Validation
When someone queries your domain, resolvers verify the entire chain of signatures from the root down, ensuring authenticity.

How to Enable DNSSEC

  1. Verify that your DNS hosting provider supports DNSSEC. Not all providers offer this feature.
  2. Log in to your DNS hosting provider's control panel.
  3. Generate DNSSEC keys (usually done automatically):
    • Zone Signing Key (ZSK) - signs individual DNS records
    • Key Signing Key (KSK) - signs the DNSKEY records
  4. Enable DNSSEC for your zone. Your provider will automatically sign all DNS records.
  5. Retrieve the DS (Delegation Signer) records from your DNS provider. These typically include:
    Key Tag: 12345
    Algorithm: 13 (ECDSAP256SHA256)
    Digest Type: 2 (SHA-256)
    Digest: ABC123...
  6. Log in to your domain registrar's control panel (where you registered the domain).
  7. Navigate to the DNSSEC settings and add the DS records provided by your DNS host.
  8. Save the changes. DNSSEC propagation can take 24-48 hours.
  9. Verify DNSSEC is working using online validation tools like dnsviz.net or dnssec-debugger.verisignlabs.com

Recommended DNSSEC Algorithms

ECDSA algorithms (13, 14) are preferred for their smaller key sizes and better performance.

DNSSEC Best Practices

Common DNSSEC Issues