Signing a zone adds several record types you did not create. Here is what each is for, and which ones you ever touch.
DNSKEY — the public key
The public half of the key pair the zone is signed with. A validating resolver fetches it to check the signatures.
Zones here are signed with two keys, which is the normal arrangement:
- A key-signing key (KSK), which signs only the DNSKEY set. Its fingerprint is what goes in the DS record at your registrar.
- A zone-signing key (ZSK), which signs everything else.
The split exists so the ZSK can be rotated often without touching the registrar, while the KSK — the one that requires a DS update — changes rarely.
You do not manage these. They are generated when you sign and rotated by the platform.
RRSIG — the signatures
One per record set, per key. If you have three A records at www, they are signed together as a set and get one RRSIG between them, not three.
RRSIGs carry their own validity window — an inception and an expiry — which is why a signed zone needs its signatures refreshed periodically rather than signed once. The platform does that; an expired signature is exactly as fatal as a wrong one.
You do not manage these either. They are written automatically and are excluded from the record editor and from your record count.
DS — the delegation signer
A hash of your KSK, published in the parent zone at the registry.
This is the only DNSSEC record you handle yourself, and the only one not in your zone. KumoDNS shows you the value; you give it to your registrar. See the DS record.
NSEC3 — proving something does not exist
A signed zone has to prove absence as well as presence. If someone asks for a name you never created, the "no such name" answer must be signed too — otherwise an attacker could simply delete records from an answer.
The original mechanism, NSEC, did this by pointing at the next name in the zone. That let anyone walk the chain and enumerate every name you had, which is rarely what people want.
NSEC3 hashes the names instead, so absence can still be proven without handing out a list of your subdomains. Zones here use NSEC3.
What you see in the record editor
None of the above, apart from what you already had.
DNSSEC material is deliberately excluded from the record list: RRSIG, DNSKEY, NSEC3 and NSEC3PARAM are the platform's data, not yours, and showing dozens of unreadable signatures beside your A records would bury the records you actually maintain. They are also excluded from your plan's record count, so signing a zone never costs you quota.
Related
- What DNSSEC is and how it works
- The chain of trust
- TLSA and DANE — the record type DNSSEC makes meaningful
Last reviewed 2026-09-16.
Open a ticket from the control panel, or use the contact form if you cannot sign in. If a domain is down, the status page is the fastest way to find out whether it is us.