Big protection. Even on the free plan. Meet your new DNS home
KumoDNS
Documentation

What DNSSEC is and how it works

The attack DNSSEC exists to stop, what signing actually adds to an answer, and why validation happens at the resolver rather than in the browser.

DNSSEC is often described as "encrypting DNS". It does not encrypt anything, and understanding what it actually does makes both its value and its risks obvious.

The problem

A plain DNS answer is an unsigned packet. Nothing in it proves it came from the right server — a resolver asks a question and believes whatever arrives first and looks plausible.

An attacker who can guess or observe the query can answer before the real server does. The resolver caches the forged answer and serves it to everyone behind it until the TTL expires. Every visitor goes somewhere else entirely, with no error anywhere.

What signing adds

When a zone is signed, each set of records gains an RRSIG — a cryptographic signature over that set, made with the zone's private key. The matching public key is published in the zone as a DNSKEY record.

A validating resolver fetches both, checks that the signature matches the records, and refuses the answer if it does not.

That proves two things: the records are the ones the zone's owner published, and nothing altered them in transit.

What it does not do

  • It does not encrypt. Every query and answer stays visible to anyone on the path. Privacy is what DNS-over-TLS and DNS-over-HTTPS address — a different problem.
  • It does not prove a site is trustworthy. It proves the record is genuine. A criminal's signed domain is faithfully proven to be theirs.
  • It does nothing if the resolver does not validate. The check happens at the resolver, not in the browser, and a user cannot tell the difference.

Why a signature alone is not enough

If a resolver simply trusted the key it found in the zone, an attacker who could forge answers could forge the key too, and sign their lies with it.

So the key has to be vouched for from outside the zone. That is the chain of trust, and it is the part that makes DNSSEC work — and the part that breaks domains when it is got wrong.

What KumoDNS signs with

ECDSA P-256 with NSEC3. It is offered as the default rather than as a choice, because picking a signing algorithm from a dropdown is a decision most people cannot evaluate and rarely need to.

Signatures are small, which matters when a DNS answer has roughly 1,232 bytes to work with over UDP, and it is validated everywhere.

Signing is available on paid plans. See enabling DNSSEC for the steps.

Last reviewed 2026-09-16.

Not what you needed?

Open a ticket from the control panel, or use the contact form if you cannot sign in. If a domain is down, the status page is the fastest way to find out whether it is us.

Top