DOMAIN GLOSSARYUPDATED 2026-05-06

DNSSEC

DNSSEC (DNS Security Extensions) is a set of cryptographic extensions to DNS that protect against forgery and cache poisoning. It works by signing DNS records with a chain of trust from the root zone down to the domain. DNSSEC is optional — domain owners can enable it at their registrar, and resolvers can validate signatures to detect tampered responses.

Also known as: DNS Security Extensions

In depth

Plain DNS has no built-in authentication. A compromised resolver or a man-in-the-middle attacker can return forged DNS responses, redirecting traffic to attacker-controlled servers. DNSSEC adds digital signatures to DNS records so resolvers can verify the response came from the legitimate authority.

DNSSEC works through a chain of trust. The root zone signs the .com zone's key. The .com zone signs your domain's key. Your nameservers sign individual DNS records. A validating resolver walks the chain and rejects any record whose signature does not validate.

Adoption is uneven. Most major TLDs sign their zones. Many enterprise domains enable DNSSEC. Most consumer domains do not. Validation at the resolver level varies by ISP — some do, some do not.

For domain monitoring DNSSEC is rarely a primary signal but appears in WHOIS as the "DNSSEC: signed" or "unsigned" field.

Examples

  • Cloudflare offers one-click DNSSEC for managed domains.
  • A dnssec lookup: dig +dnssec example.com — returns RRSIG records alongside standard DNS records.
  • .gov mandates DNSSEC for US federal government domains.

Frequently asked questions

Should I enable DNSSEC?

For most domains, optional. Strongly recommended for high-value targets (banking, government, large brands). The downside is operational complexity — misconfigured DNSSEC can break the domain.

How do I enable DNSSEC?

In your registrar dashboard. The exact path varies. Most major registrars support one-click DNSSEC for domains using the registrar's default DNS.

Can DNSSEC break my domain?

Yes if misconfigured. Common failure: changing nameservers without updating the DNSSEC delegation, which makes signatures invalid and breaks resolution. Always update DNSSEC records when changing nameservers.

Is DNSSEC the same as HTTPS?

No. HTTPS protects the connection between your browser and a server. DNSSEC protects the DNS lookup that finds the server. Both are useful; they protect different layers.

How widely is DNSSEC deployed?

Most major TLDs sign their zones. About 30% of resolved DNS queries are validated. Specific use varies by registry, registrar, and ISP.

Related terms

References

Watch a domain you want to buy — snooze.domains tracks the lifecycle and emails you when it changes status. Free, up to 100 domains. Start watching — free