DNSSEC adds digital signatures to your DNS records, ensuring visitors always reach the real IP address of your domain instead of a spoofed server. Without DNSSEC, DNS traffic can be manipulated, allowing visitors to be unknowingly redirected to a fake website. In this article, you’ll learn exactly what DNSSEC does, why it matters, and how to activate it for your domain.
What DNSSEC is and how it works
DNS translates a domain name like tandata.io into an IP address. Standard DNS has no built-in check to verify that the response actually comes from the correct source. DNSSEC (Domain Name System Security Extensions) solves this by adding a digital signature to every DNS response. The resolver that receives the response checks this signature using a public key. If the signature doesn’t match, the response is rejected.
This works through a chain of trust: from the root servers, through the registry of the extension (such as SIDN for .nl), all the way to your own domain. Each link signs the key of the next link, making forgery theoretically impossible without it being noticed.
Why DNSSEC is important for your domain
Without DNSSEC, a domain is vulnerable to DNS spoofing and cache poisoning: techniques in which an attacker inserts false DNS responses. Visitors think they’re on your website, but in reality end up on a phishing site attempting to steal, for example, login credentials or payment details.
For businesses using business email, this is especially relevant, since email traffic is also routed via DNS. A spoofed DNS response can cause email to be sent to the wrong server. DNSSEC prevents this and forms a logical addition to measures such as SPF, DKIM, and DMARC.
Enabling DNSSEC: step by step
Enabling DNSSEC happens in two places: with your hosting provider or DNS manager, and with the registrar where your domain is registered. Both need to align, otherwise the chain of trust won’t work.
Check whether your DNS zone supports DNSSEC
Your DNS management environment must be capable of signing records. In Plesk, you’ll find this option under your DNS settings, alongside the other options for your domain names.
Enable DNSSEC for the zone
Activate the feature in your DNS management environment. This automatically generates the required keys and signs your DNS records.
Retrieve the DS record
After activation, a DS record (Delegation Signer) is created. You need to pass this record on to your registrar so the registry knows your domain uses DNSSEC.
Add the DS record at the registrar
Log in to your domain’s registrar and add the DS record to the domain settings. This is the step that actually closes the chain of trust.
Verify the configuration
Use an online DNSSEC validation tool to check whether the chain is correctly built and your domain is validated properly.
Common mistakes and points of attention
The most common mistake is that the DS record has been created but not (or incorrectly) submitted to the registrar. This creates a broken chain of trust and can make your domain unreachable for resolvers that enforce DNSSEC.
Also pay attention when making changes to your DNS records after DNSSEC is active: every change needs to be re-signed. Most modern DNS management environments do this automatically, but manual zone files can cause issues.
Considering switching to another provider? Make sure DNSSEC is properly aligned between the old and new provider before completing the transfer. Check out the information on switching to Tandata. If you run into any issues during configuration, you’ll find detailed explanations in our knowledge base.
Frequently Asked Questions
Does DNSSEC cost extra?
This varies by provider and registry. Check with your hosting provider or registrar for the terms applicable to your specific domain extension.
Does DNSSEC work for every domain extension?
Not every extension supports DNSSEC. Commonly used extensions such as .nl and .com do support it, but check with the registry of your extension if in doubt.
Does DNSSEC affect the speed of my website?
No, DNSSEC only affects the DNS lookup, not the loading time of your web hosting or your server’s performance.
Can I disable DNSSEC again?
Yes, but do this carefully. First remove the DS record at the registrar and wait until this change takes effect before disabling DNSSEC on the DNS zone.
Does DNSSEC also protect my email?
DNSSEC protects the DNS lookup that’s also used for email, but for complete email security, SPF, DKIM, and DMARC remain necessary. Learn more at business email.
Conclusion
DNSSEC adds an important security layer to your domain by digitally signing and validating DNS responses. Enabling it requires careful configuration both in your DNS management environment and at your registrar, but it effectively protects your visitors against DNS spoofing. Want this properly set up without hassle? Check out the options our web hosting offers.