Big protection. Even on the free plan. Meet your new DNS home
KumoDNS
Documentation

DNSSEC terms, briefly

A short glossary of the acronyms DNSSEC documentation assumes you know — and which of them you ever have to touch.

DNSSEC documentation, including ours, uses a lot of acronyms. This is what they mean and whether you ever deal with them.

TermWhat it isYours to manage?
DNSKEYThe public key published in your zoneNo — generated on signing
KSKKey-signing key. Signs the DNSKEY set; its hash is the DSNo
ZSKZone-signing key. Signs everything elseNo
RRSIGA signature over one record setNo — written automatically
RRSETAll records of one type at one name, signed togetherNo
DSDelegation signer — a hash of your KSK, at the registryYes
NSEC / NSEC3Signed proof that a name does not existNo — NSEC3 here
Trust anchorThe root's key, known to resolvers in advanceNo
Chain of trustRoot vouches for TLD, TLD vouches for you—
ValidationThe resolver's check that signatures hold—
SERVFAILWhat a resolver returns when validation fails—
ad flagAuthenticated data — validation succeeded—
+cdChecking disabled — ask a resolver to skip validation—

Only one row says yes. That is the useful summary: of everything DNSSEC involves, the DS record at your registrar is the only piece you handle, and it is where essentially every failure comes from.

Two commands worth remembering

dig +short DS example.com      # what the parent publishes about you
dig +cd example.com @1.1.1.1   # the same query, without validation

The first tells you whether the chain is joined. The second, compared against the same query without +cd, tells you whether validation is the thing failing.

Last reviewed 2026-09-16.

Not what you needed?

Open a ticket from the control panel, or use the contact form if you cannot sign in. If a domain is down, the status page is the fastest way to find out whether it is us.

Top