DNSSEC signs your zone so a resolver can prove the answer it received is the answer we published, and was not changed in transit.
Available on every paid plan. Not on free.
Signing
Signing is a single action on the zone. Keys are generated, the zone is signed, and key rollover is handled for you afterwards. There is no key material for you to store, back up or remember to rotate.
The step that is not optional
Signing the zone here does nothing until you publish the DS record at your registrar.
The portal shows the DS record after signing. Copy it into your registrar's DNSSEC section. Until that exists, the zone is signed but the chain of trust is not connected, and resolvers treat it as unsigned — you get the work and none of the protection.
The one real risk, stated plainly
A DS record that does not match the key here takes the domain offline. Not "degrades" — a validating resolver refuses the answer entirely, and most of the internet validates.
That happens in three ways:
- The DS is published at the registrar and the zone is then unsigned here.
- The zone is moved to another DNS provider while the DS is still in place.
- A DS is entered by hand and mistyped.
So the order matters, in both directions:
- Turning DNSSEC on: sign here first, then publish the DS at the registrar.
- Turning DNSSEC off: remove the DS at the registrar first, wait for it to expire from caches, and only then unsign here.
Get that second order wrong and the domain fails to resolve for as long as the old DS is cached — which can be a day.
Checking it worked
dig example.com DS +short
dig example.com A +dnssec
The first should show the DS at your registrar. The second should return an RRSIG alongside the answer. A sudden rise in SERVFAIL after enabling DNSSEC almost always means the DS and the key disagree.
Last reviewed 2026-08-19.
Open a ticket from the control panel, or use the contact form if you cannot sign in. If a domain is down, the status page is the fastest way to find out whether it is us.