DNS Management & Nameservers

Implementing DNSSEC on DomainIndia.com

By the Domain India teamPublished 5 min read
Knowledge base article
Contents (4 sections)

DNSSEC is not a self-service switch in the Domain India client area. DNSSEC needs two parts: your DNS host signs your zone, and a matching DS record is published at the registry through the registrar that holds the domain. Because a wrong DS record takes a domain offline, any DS record request goes through a support ticket, and support will tell you what is possible for your domain before anything is changed.

For the full guide

How DNSSEC works, how to sign a zone and how to troubleshoot it is covered in DNSSEC explained. To check whether your extension is signed, see the list of extensions that support DNSSEC.

Key takeaways

There is no DNSSEC or DS record page in the Domain India client area. First make sure whoever hosts your domain's DNS can sign the zone and give you a DS record, then open a support ticket with the domain name and your DNS provider. Support will tell you what is possible for that domain before anything is changed. The .in, .co.in and .com extensions are all signed at the registry.

1. What has to happen for DNSSEC to work

  1. Check the extension is signed.
    Almost every common extension is, including .in, .co.in, .com, .net and .org. Run dig DS in. +short (with your extension in place of in) to confirm.
  2. Sign the zone at your DNS host.
    The DNS host is whoever runs the nameservers your domain points to. Many managed DNS providers sign a zone with one switch and then show you the DS record details: key tag, algorithm, digest type and digest.
  3. Ask support about the DS record.
    Open a support ticket with the domain name, the name of your DNS provider and the DS record details. Support will confirm what can be done for that domain and extension.
  4. Check the result.
    After the change, run dig DS yourdomain.in +short and check the domain on DNSViz (dnsviz.net). A validating resolver sets the ad flag in dig +dnssec output.
Never publish a DS record the zone doesn't match

If the DS record at the registry does not match the keys your DNS host signs with, validating resolvers reject your domain and your website and email stop working for many users. Only send a DS record that your current DNS host gave you, after the zone is signed.

2. If your domain uses Domain India hosting

The DS record is a registry setting, so it is never entered in a hosting control panel's DNS zone editor. Whether the DNS on your hosting server can sign your zone is not something to assume; ask support in the same ticket, and we will tell you what is possible for your account.

3. If your DNS is hosted elsewhere

Turn on DNSSEC at that provider first, copy the DS record details it shows you, and include them in your ticket. Keep the provider's DNSSEC settings on for as long as the DS record is published.

4. Moving nameservers on a signed domain

Before you point a DNSSEC-signed domain at new nameservers, ask support to remove the DS record, wait a day or two for caches to expire, then move. Set DNSSEC up again once the new DNS host is signing the zone. Changing nameservers with an old DS record still in place is the most common way a signed domain goes offline. Nameserver changes themselves are covered in how do I change my nameservers.

Can I turn on DNSSEC from the Domain India client area?

No. There is no DNSSEC or DS record page in the client area. Open a support ticket with the domain name and your DNS provider, and support will tell you what is possible for that domain.

Do .in domains support DNSSEC?

Yes. The .in zone and its second-level extensions such as .co.in are signed at the registry. Your own domain is protected only after its DNS host signs the zone and a matching DS record is published.

Where do I get the DS record details?

From whoever hosts your domain's DNS. After that provider signs the zone, it shows the key tag, algorithm, digest type and digest for the DS record.

Do I need DNSSEC for my website to work?

No. DNSSEC adds protection against forged DNS answers, but a domain works normally without it. To connect a domain to hosting, point it at the hosting nameservers.

What should I do before changing nameservers on a DNSSEC domain?

Ask support to remove the DS record first, wait a day or two, then change the nameservers, and set DNSSEC up again at the new DNS host.

Ready to set it up? Read DNSSEC explained, confirm your DNS host can sign the zone, then open a ticket with the DS record details.

Want DNSSEC on your domain?

Send us the domain name and your DNS provider, and we will tell you what is possible for that domain before anything is changed.

Open a ticket

Ready when you are

Find your domain

Search domains

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
DNSSEC for Domain India Domains: How to Request It