NameBright Help Center

What Is DNSSEC And How Does It Work?

Add DNSSEC To Your Domain

If you are using NameBright’s Nameservers:

  1. Once you are logged in to NameBright, navigate to My Domains.

  2. Select a domain.

  3. Within the DNS Records section, click Manage DNS.

    Manage%20DNS%20Icon

  4. Select the DNSSEC tab.

  5. Click or tap on the Enable DNSSEC toggle switch. It will slide from the "Off" position to the "On" position. DNSSEC is now enabled for your domain.

If you are not using NameBright’s Nameservers:

  1. Follow the instructions at your DNS provider to enable DNSSEC for your domain.

  2. Once you are logged in to NameBright, navigate to My Domains.

  3. Select a domain.

  4. Within the DNS Records section, click Manage DNS.

  5. Select the DS Records tab.

  6. Click Add DS Record.

  7. Edit the record and click Add DS Record.

  8. Your record will now display on the DNSSEC tab.

Note that not all registries support KeyData. If you encounter an error when creating a DNSSEC record, remove the Key Tag. If that fails, attempt to create it using only the Key Tag.

Your domain should now pass DNSSEC validation. To test, use a service such as: https://dnssec-analyzer.verisignlabs.com/


Learn More About DNSSEC

  • What Is DNSSEC?

  • Benefits Of Using DNSSEC

  • DNSSEC And Blockchain

  • Is DNSSEC Necessary?

  • DNSSEC Record Providers

  • Add DNSSEC To Your Domain

What Is DNSSEC?

DNSSEC (Domain Name System Security Extensions) is a set of protocols designed to enhance the security of the Domain Name System (DNS). DNSSEC provides a way to verify the authenticity and integrity of DNS data. 

DNSSEC works by digitally signing DNS records, ensuring that users receive legitimate responses from DNS queries and preventing malicious alterations of DNS data.

Benefits Of Using DNSSEC

DNSSEC enhances security by verifying DNS data integrity, helping to ensure that users are directed to legitimate websites and services, reducing the risk of fraud and data breaches.

  1. Trust and Confidence: DNSSEC establishes a chain of trust from the root DNS servers down to the authoritative DNS servers for individual domains. Each level in this chain can verify the signatures of the level above it, creating a secure hierarchy that helps in ensuring the overall integrity and authenticity of DNS data.

  2. Compliance: DNSSEC helps meet security standards and regulatory requirements that mandate DNSSEC implementation for secure operations.

  3. Authentication: DNSSEC uses public-key cryptography to sign DNS data. This means that when a DNS resolver receives a DNS response, it can verify the digital signature to confirm that the response indeed comes from the legitimate DNS server and not from an attacker. This helps in preventing various types of attacks, such as cache poisoning and man-in-the-middle attacks.

DNSSEC And Blockchain

DNSSEC enhances the security of blockchain and cryptocurrency systems by protecting the integrity of domain name resolution. 

By ensuring that domain name responses are verified and authentic, DNSSEC helps maintain the integrity of the network’s interactions, ensuring that users connect to legitimate blockchain platforms and crypto services. This extra layer of verification makes it harder to alter or forge DNS information.

Is DNSSEC Necessary?

Although DNSSEC is not required, it does enhance your website or organization's security by verifying DNS data authenticity. This is especially important for handling sensitive information, meeting regulatory requirements, or fostering user trust. However, DNSSEC requires careful setup and maintenance, so ensure your team is equipped to manage it and that your DNS provider supports it. 

Several industries and countries have recognized the importance of DNSSEC and implemented regulations or initiatives to mandate its use for enhanced security. Here are some examples:

  1. Government Agencies and Critical Infrastructure: The U.S. Department of Homeland Security has encouraged the adoption of DNSSEC across federal domains to protect critical infrastructure and enhance overall cybersecurity. The EU Agency for Cybersecurity (ENISA) has recommended DNSSEC adoption to improve the security of public and private sector domains. Additionally, other countries such as Estonia and Sweden, are pioneers in digital security and have actively promoted DNSSEC adoption.

  2. Financial Institutions Worldwide: Many financial institutions, including banks and cryptocurrency exchanges, implement DNSSEC to protect against phishing and domain spoofing attacks, ensuring secure online transactions and communications.

  3. Telecommunications Industry: Several telecom companies and ISPs adopt DNSSEC as part of their security measures to safeguard network infrastructure and prevent DNS-related attacks.

These regulations and initiatives reflect a growing recognition of DNSSEC's role in enhancing online security and protecting against various cyber threats.

DNSSEC Record Providers

A DNSSEC record provider is a service or entity that supports the creation, management, and distribution of DNSSEC-related records for domain names. DNSSEC record providers can include:

  • Domain Registrars: Companies that register and manage domain names, often providing DNSSEC support as part of their services.

  • DNS Hosting Providers: Services that manage DNS records for domains and implement DNSSEC to ensure secure and accurate DNS resolution.

  • Managed DNS Services: Specialized providers offering advanced DNS services, including DNSSEC implementation and management.