DNS Management & Nameservers

Comprehensive List of TLDs Supporting DNSSEC

By the Domain India teamPublished 7 min read
Knowledge base article
Contents (6 sections)

DNSSEC adds digital signatures to DNS answers so that resolvers can detect forged or tampered records. For your domain to be protected, its extension (the TLD, such as .in or .com) must itself be signed, and that is now true of almost every extension in common use. This page lists the popular extensions we checked, shows you how to check any other extension yourself, and explains the two further steps a domain needs before DNSSEC actually protects it.

Key takeaways

Almost all widely used extensions are signed with DNSSEC, including .in and its second-level extensions (.co.in, .net.in, .org.in), .com, .net, .org and most new extensions. A signed TLD alone does not protect your domain: your DNS provider must also sign your zone, and a matching DS record must be published through your registrar. You can check any extension in seconds with dig DS in. +short (with any extension in place of in). A wrong DS record takes a domain offline, so plan before you switch it on.

New to DNSSEC?

This page is about which extensions support DNSSEC. For how DNSSEC works, its record types (DNSKEY, RRSIG, DS) and troubleshooting, read DNSSEC explained.

We checked each of these extensions for a DS record in its parent zone (the root zone, or the .in zone for .co.in and its siblings) on 23 September 2026. A DS record at the parent means the extension is signed and can carry DNSSEC for domains under it.

ExtensionSigned (DS record present)Notes
.inYesIndia's country code
.co.in, .net.in, .org.inYesSecond-level .in extensions
.भारतYesIndia's Hindi-script extension
.com, .netYesVerisign-run global extensions
.org, .infoYesGlobal extensions
.xyz, .online, .storeYesNewer generic extensions
.io, .coYesCountry codes used generically
.app, .devYesGoogle-run extensions
.uk, .ca, .auYesOther country codes

This is a sample, not a full list. Registries sign and occasionally re-sign their zones, so check the extension you care about at the time you need it, using the method below.

2. Check any extension yourself

You don't need a list that goes out of date. Ask DNS directly whether the extension has a DS record in its parent zone.

  1. Open a terminal.
    On Windows, use PowerShell with Resolve-DnsName -Type DS in, or use dig inside WSL. On macOS and Linux, dig is usually already installed.
  2. Query the extension's DS record.
    Run dig DS in. +short, replacing in with the extension you want. Note the full stop after it.
  3. Read the answer.
    One or more lines of numbers and a long hexadecimal string means the extension is signed. An empty answer means it is not signed, or you mistyped it.
  4. Check your own domain the same way.
    Run dig DS yourdomain.in +short. An empty answer means DNSSEC is not active for your domain, even if the extension supports it.
bash
dig DS in. +short
dig DS co.in. +short
dig DS yourdomain.in +short
dig +dnssec yourdomain.in A

The last command asks for your domain's A record with signatures. If your resolver validates DNSSEC, look for the ad (authenticated data) flag in the header. Online checkers such as DNSViz draw the whole chain of trust from the root to your domain, which is the easiest way to spot a broken link.

3. A signed extension is only the first step

DNSSEC works as a chain. Every link must be in place:

The extension is signed
The registry signs the TLD zone and its parent zone holds a DS record for it. Section 1 shows this is true for all the popular extensions.
Your zone is signed
Whoever hosts your domain's DNS (the servers your nameservers point to) must sign your records and publish DNSKEY records.
A DS record is published
A DS record matching your zone's key must be sent to the registry through your registrar, so the extension vouches for your key.

If your DNS host signs the zone but no DS record is published, nothing is protected; resolvers treat the domain as unsigned. If a DS record is published but the zone is not signed, or is signed with a different key, validating resolvers reject your domain's answers and your website and email stop working for their users.

A wrong DS record takes your domain offline

Never add or change a DS record by hand unless it comes from your current DNS host. Before you move a DNSSEC-signed domain to new nameservers, remove the DS record first and wait for it to expire from caches, then move, then set DNSSEC up again at the new DNS host.

4. Should you turn DNSSEC on?

DNSSEC protects visitors against DNS spoofing and cache poisoning, where an attacker feeds a resolver a false address for your domain. It does not encrypt anything and does not replace HTTPS; you still need an SSL certificate on your website.

Worth it if
  • Your DNS provider signs zones and handles key rollovers automatically
  • You run payments, logins or other sensitive services on the domain
  • You want email security features such as DANE, which need DNSSEC
Think twice if
  • You change DNS providers often, or your provider needs manual key handling
  • Nobody on your team will notice if the DS record and the keys drift apart

5. DNSSEC for domains registered with Domain India

Domain India is a NIXI-accredited .IN registrar, and every extension listed in section 1 is signed at the registry. Whether DNSSEC can be switched on for a particular domain depends on where its DNS is hosted and on the extension, so we don't promise it for every domain. If you want DNSSEC for a domain registered with us, open a support ticket with the domain name and the name of your DNS provider before you change anything, and we will tell you what is possible for that domain.

If you just want your domain working with your hosting, you don't need DNSSEC for that. Point the domain at your hosting nameservers as described in how do I change my nameservers.

Frequently asked questions

Does the .in extension support DNSSEC?

Yes. The .in zone and its second-level extensions such as .co.in, .net.in and .org.in are signed, with DS records in their parent zones. You can confirm it yourself by running dig DS in. +short.

Does .com support DNSSEC?

Yes. The .com zone is signed and has a DS record in the root zone. For a .com domain to be protected, its DNS host must also sign the zone and a DS record must be published through the registrar.

How do I check whether an extension supports DNSSEC?

Run dig DS followed by the extension and a full stop, for example dig DS in. +short. Any answer means the extension is signed; an empty answer means it is not.

How do I check whether DNSSEC is active on my own domain?

Run dig DS yourdomain.in +short. An empty answer means no DS record is published and DNSSEC is not active for your domain. A tool such as DNSViz shows the whole chain of trust.

Is DNSSEC the same as SSL?

No. DNSSEC proves that DNS answers for your domain are genuine. SSL/TLS encrypts the connection between a visitor and your website. They protect against different attacks, so a site that uses DNSSEC still needs SSL.

Can a DNSSEC mistake take my website offline?

Yes. If the DS record at the registry does not match the keys your DNS host signs with, validating resolvers reject your domain's answers and your website and email become unreachable for their users. Remove the DS record before changing DNS providers.

Ready to secure your domain? Check your extension with the commands above, read DNSSEC explained for the details, and if your domain is registered with us, open a support ticket before you enable anything. Looking for a new name? Search for a domain.

Register your domain with a NIXI-accredited registrar

Search .in, .co.in, .com and hundreds more extensions, with first-year and renewal prices shown side by side.

Search domains

Ready when you are

Find your domain

Search domains

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Which TLDs Support DNSSEC? List and How to Check