Skip to main content
Version: 2.1.26

DNSSEC

DNSSEC (/domains/dnssec) signs one of your DNS zones and keeps it signed.

The page separates two questions that are easy to confuse:

  • Enabled — the zone is signed on this server. That happens as soon as you turn it on.
  • Validating — the parent zone publishes your DS record. Until your registrar has been given that record, DNSSEC is doing nothing at all.

So the page shows you the DS records to hand your registrar (there are two during a key rollover), and what the parent zone publishes today.

It also shows the signing algorithm, the age of the key-signing and zone-signing keys and when each is due to rotate, and how long the earliest signature in the zone has left. Signatures are re-made by a daily timer well before they expire; a number heading towards zero means that timer is not running.