DNS turns a domain name into the addresses your browser and mail server connect to, but plain DNS has no way to prove an answer is genuine. DNSSEC (DNS Security Extensions) adds digital signatures to DNS records so that a resolver can check that an answer really came from the domain's DNS host and was not altered on the way. This guide explains how DNSSEC works, what it takes to switch it on safely, and how to check and troubleshoot it.
DNSSEC signs your DNS records so resolvers can detect forged answers, which protects visitors against DNS spoofing and cache poisoning. It needs two things: your DNS host must sign your zone, and a matching DS record must be published at the registry through your registrar. Almost every common extension, including .in and .com, is already signed. A DS record that doesn't match your keys takes the domain offline, so set it up carefully, and for a domain registered with Domain India, ask support before adding a DS record.
1. What DNSSEC is, and what it is not
DNSSEC is a set of standards that adds cryptographic signatures to DNS data. When a validating resolver (for example your ISP's resolver, or a public one such as Google Public DNS, Cloudflare or Quad9) looks up a signed domain, it checks each signature. If a signature is missing or wrong, the resolver refuses the answer instead of passing a forged address to the visitor.
It helps to be clear about the limits:
- DNSSEC proves authenticity, not secrecy. DNS answers are still readable by anyone on the path. Encryption of DNS queries is a separate topic (DNS over HTTPS or TLS).
- DNSSEC does not replace SSL/TLS. Your website still needs an HTTPS certificate. DNSSEC stops a visitor being sent to the wrong server; TLS protects the connection once they get there.
- DNSSEC does not stop a hijack at the registrar. If someone takes over your registrar account and changes nameservers, DNSSEC cannot help. Protect that account with a strong password and two-factor authentication.
2. Why it matters
DNSSEC is most valuable for domains that handle logins, payments or email that others rely on. For a small brochure site the benefit is smaller, and the main cost is operational care, covered in section 7.
3. How the chain of trust works
DNSSEC works as a chain from the root of the DNS down to your domain. Each level vouches for the key of the level below it.
- The root zone is signed.Validating resolvers ship with the root's public key (the trust anchor).
- The extension is signed.The root publishes a DS record for each signed extension, such as .in or .com. The .in zone in turn publishes DS records for .co.in, .net.in and the other second-level .in extensions.
- Your zone is signed.Your DNS host signs your records and publishes your public keys as DNSKEY records.
- A DS record links the two.A DS record for your domain, published in the extension's zone through your registrar, contains a hash of your key. That is how the extension vouches for you.
- The resolver validates.When someone looks up your domain, the resolver follows the chain from the root to your records and checks every signature on the way.
If any link is missing, the domain is treated as unsigned (no protection, but it still works). If a link is present but wrong, the domain fails validation and stops resolving for everyone who uses a validating resolver.
4. The DNSSEC record types
| Record | What it holds | Where it lives |
|---|---|---|
| DNSKEY | Your zone's public keys | Your zone, at your DNS host |
| RRSIG | A signature over a set of records, such as all your A records | Your zone, created by your DNS host |
| DS | A hash of your key-signing key, which links your zone to its parent | The parent zone (the extension), submitted through your registrar |
| NSEC or NSEC3 | Signed proof that a name or record type does not exist | Your zone, created by your DNS host |
| CDS and CDNSKEY | Your DNS host's request for the parent to update the DS record | Your zone; used only where the registry supports automated updates |
Zone-signing and key-signing keys
Most setups use two keys. The zone-signing key (ZSK) signs your everyday records. The key-signing key (KSK) signs only the DNSKEY set, and it is the key the DS record at the parent points to. Splitting them means the ZSK can be changed without touching the registry. Some modern setups use one combined signing key (CSK) instead, which is fine too.
Algorithms in 2026
Choose ECDSA P-256 with SHA-256 (algorithm 13) for new setups. It gives small signatures and is what most large zones, including .in and .com, now use. RSA with SHA-256 (algorithm 8) is still valid. Avoid anything based on SHA-1 (algorithms 5 and 7), and use digest type 2 (SHA-256) for DS records, not digest type 1.
5. Setting up DNSSEC for a domain
How you switch it on depends almost entirely on who hosts your DNS.
If a managed DNS provider hosts your DNS
Many DNS providers, for example Cloudflare, sign zones for you with one switch. The provider then shows you the DS record details: a key tag, an algorithm number, a digest type and a digest (a long hexadecimal string). That DS record then has to be published at the registry through your registrar. The provider also handles key rollovers, which is the hard part.
If you run your own DNS server
On your own server or VPS, current versions of BIND and Knot DNS can sign a zone and roll its keys automatically. In BIND 9.18 and later, you attach a policy to the zone instead of generating keys by hand:
zone "example.com" {
type primary;
file "example.com.zone";
dnssec-policy default;
inline-signing yes;
};The built-in default policy uses ECDSA P-256 and manages the keys for you. Older guides that run dnssec-keygen and dnssec-signzone by hand still work, but they leave you responsible for re-signing the zone before signatures expire, which is a common cause of outages. Once the zone is signed, read the DS record from your server (for example with dnssec-dsfromkey) and have it published at the registry.
Publishing the DS record
The DS record is the step that makes DNSSEC live, and it goes to the registry through the registrar that holds your domain. For domains registered with Domain India, the client area does not currently have a self-service DS record page. Open a support ticket with the domain name and the name of your DNS provider, and support will tell you what is possible for that domain before anything is changed.
Only publish a DS record that your current DNS host gave you, and only after the zone is actually signed. A DS record that does not match the keys in your zone makes validating resolvers reject every answer, so your website and email stop working for a large share of internet users.
6. Checking DNSSEC
You can check any domain from a terminal. dig is available on macOS and Linux, and in WSL on Windows.
# Is the extension signed? Any answer means yes.
dig DS in. +short
# Is a DS record published for your domain?
dig DS yourdomain.in +short
# Does your zone publish keys?
dig DNSKEY yourdomain.in +short
# Ask a validating resolver and look for the "ad" flag in the header
dig @1.1.1.1 +dnssec yourdomain.in A
# Full validation trace from the root (BIND's delv tool)
delv yourdomain.in A +vtraceIn the dig output, flags: qr rd ra ad means the resolver validated the answer. If the domain is signed but a validating resolver returns SERVFAIL while dig +cd (checking disabled) returns an answer, DNSSEC validation is failing.
Online tools draw the whole chain for you, which is the fastest way to find a broken link:
- DNSViz (dnsviz.net) shows every level from the root to your records and highlights errors.
- Verisign DNSSEC Analyzer (dnssec-analyzer.verisignlabs.com) lists each check with a pass or fail.
- Internet.nl tests DNSSEC together with other standards such as IPv6 and HTTPS.
7. Running DNSSEC without breaking your domain
Most DNSSEC outages come from routine changes, not attacks.
- Let your DNS software or provider handle signing and key rollovers automatically
- Remove the DS record first, wait a day or two for caches to expire, and only then move to new nameservers or a new DNS provider
- Check the domain with DNSViz after every DNS provider change or key rollover
- Protect your registrar account with two-factor authentication
- Adding a DS record before the zone is signed
- Changing nameservers while an old DS record is still published
- Hand-signed zones with nobody watching the signature expiry dates
- SHA-1 algorithms or digest type 1 for new keys
On key rollovers: current guidance no longer calls for rotating keys every few months. Automated tools roll the zone-signing key on their own schedule; a KSK rollover needs a DS change at the registry and should be planned, not rushed. For NSEC3, current best practice (RFC 9276) is zero extra iterations and no salt, which is what BIND's default policy does.
Common failures and what they mean
| Symptom | Likely cause | Fix |
|---|---|---|
| Site works on some networks, SERVFAIL on others | DS record does not match the zone's keys | Correct or remove the DS record at the registry |
| Everything fails after moving DNS provider | Old DS record still points to the previous provider's key | Remove the DS record, wait, then set DNSSEC up again at the new provider |
| Failures start days after setup | Signatures expired on a hand-signed zone | Re-sign the zone and switch to automatic signing |
| dig DS shows nothing | No DS record published, so DNSSEC is not active | Publish the DS record from your DNS host through your registrar |
8. Which extensions support DNSSEC
Almost all extensions in common use are signed, including .in and its second-level extensions such as .co.in, .com, .net and .org. You can confirm any extension with dig DS in. +short (replacing in). For a checked list of popular extensions, read the list of extensions that support DNSSEC.
9. DNSSEC and Domain India
Domain India is a NIXI-accredited .IN registrar, and the extensions we sell most, such as .in, .co.in and .com, are signed at the registry. Whether DNSSEC can be enabled for a particular domain depends on where its DNS is hosted and on the extension, so we don't promise it for every domain. If you want DNSSEC on a domain registered with us, open a ticket with the domain name and your DNS provider before you change anything.
If you only need your domain to work with your hosting, you don't need DNSSEC for that. Point the domain at your hosting nameservers as described in how do I change my nameservers.
What does DNSSEC do?
DNSSEC adds digital signatures to a domain's DNS records. Validating resolvers check those signatures and reject forged or altered answers, which protects visitors against DNS spoofing and cache poisoning.
Is DNSSEC the same as SSL?
No. DNSSEC proves that DNS answers for a domain are genuine. SSL/TLS encrypts the connection between a visitor and the website. A site that uses DNSSEC still needs an SSL certificate.
Does .in support DNSSEC?
Yes. The .in zone and its second-level extensions such as .co.in are signed. You can confirm it by running dig DS in. +short, which returns a DS record.
What is a DS record?
A DS (Delegation Signer) record is a hash of a domain's key-signing key, published in the extension's zone through the registrar. It links the extension to the domain's own keys and completes the chain of trust.
How do I add a DS record for a domain registered with Domain India?
There is no self-service DS record page in the client area. Open a support ticket with the domain name and your DNS provider, and support will tell you what is possible for that domain before anything is changed.
How can I tell whether DNSSEC is active on my domain?
Run dig DS yourdomain.in +short. An empty answer means no DS record is published and DNSSEC is not active. DNSViz shows the whole chain of trust and highlights errors.
Can DNSSEC take my website offline?
Yes, if it is set up wrongly. A DS record that does not match the zone's keys, or expired signatures, make validating resolvers reject the domain, so the website and email stop working for their users.
Ready to secure your domain? Check your extension and domain with the commands above, see the list of extensions that support DNSSEC, and for a domain registered with us, open a ticket before you publish a DS record. Looking for a new name? Search for a domain.
Search .in, .co.in, .com and hundreds more extensions, with first-year and renewal prices shown side by side.
Search domains