What Is DNSSEC and How Do I Manage DS Records?

DNSSEC for .UK domains

DNSSEC helps prove that DNS answers are authentic

DNSSEC digitally signs DNS data so compatible networks can detect altered or forged answers. It does not encrypt website traffic or replace an SSL certificate. For eligible .UK domains, UKC lets the account owner publish and manage the exact DS records supplied by the DNS provider that signs the domain.

PROTECTSDNS authenticityDetects changed answers
REQUIRESA signed DNS zoneYour DNS provider creates the keys
CONNECTSA DS record at NominetCompletes the chain of trust

How does DNSSEC work?

Normal DNS translates names such as yourdomain.co.uk into the addresses used by websites and email. DNSSEC adds digital signatures that allow a validating resolver to check that a DNS answer came from the expected source and was not changed in transit.

1. Your DNS provider signs the zone

The provider hosting your DNS creates and maintains cryptographic keys, then signs the domain’s DNS records.

2. The provider supplies DS values

It gives you a key tag, algorithm, digest type and digest that identify the signed key.

3. You publish the DS at Nominet

For an eligible UKC-managed .UK domain, enter those exact values in the Client Area. UKC sends the DS record to the .UK registry.

4. Resolvers validate the chain

Compatible resolvers follow the signed chain from the .UK parent zone to your domain and reject answers that fail validation.

Who should use DNSSEC?

DNSSEC is useful when the DNS provider actively supports zone signing and can supply and maintain the correct DS information.

Consider using it

Your business relies on its domain, your DNS provider supports DNSSEC and you want stronger protection against forged DNS answers.

Good for managed DNS

Your specialist DNS provider signs the zone, displays the DS values and gives clear instructions for key changes.

Use it with a maintenance plan

You or your provider can coordinate nameserver changes, DNS provider moves and key rollovers without leaving a stale DS record.

Do not enable it blindly

Do not invent DS values or add them before the DNS zone is signed. If the provider does not offer DNSSEC, there is nothing valid to publish.

What does DNSSEC protect?

Security needDoes DNSSEC help?What else is needed?
Detect forged or altered DNS answersYesThe DNS zone must be signed and the DS record must be correct
Prove DNS data came from the expected signed zoneYesA validating resolver must perform the checks
Encrypt website trafficNoUse HTTPS with a valid SSL certificate
Encrypt email connectionsNoUse the secure IMAP and SMTP settings supplied for the mailbox
Remove malware or secure a compromised websiteNoUse website security, updates, backups and malware protection

How do I add a DS record in the UKC Client Area?

The DNS provider that signs your zone must give you the values first. Copy them exactly and do not convert or shorten the digest.

  1. 1
    Enable signing at the DNS provider

    Follow the provider’s DNSSEC setup. Wait until it confirms that the domain’s DNS zone is signed and shows the DS record.

  2. 2
    Open DNSSEC Setup

    Sign in to the UKC Client Area, open My Domains, choose the eligible .UK domain and select DNSSEC Setup.

  3. 3
    Copy all four values exactly

    Enter the key tag, algorithm, digest type and digest supplied by the DNS provider. Review every character before continuing.

  4. 4
    Confirm and verify

    Review the proposed registry change, type the domain when asked and submit it. Reopen the tab to confirm the DS record shown by Nominet matches the provider.

What are the four DS record fields?

FieldMeaningWhat to enter
Key tagA short numeric identifier for the DNSSEC keyCopy the number supplied by the DNS provider
AlgorithmThe code for the signing algorithmSelect the exact algorithm number supplied
Digest typeThe code for the method used to create the digestSelect the exact digest type supplied
DigestThe long hexadecimal fingerprint of the keyPaste the complete value with no spaces

How should I change or remove DS records?

Key rollover

Follow the DNS provider’s sequence. A rollover can temporarily require both the old and new DS records. Remove the old record only when the provider says it is safe.

Changing DNS provider

Coordinate signing, nameservers and DS records as one migration. Do not leave a DS record pointing to keys that the new provider does not use.

Turning DNSSEC off

Use the provider’s secure transition process. Do not stop signing while a valid DS record is still expected by cached resolvers.

Recovering from an error

Compare the live registry record with the provider’s current values. If the website or email is failing, contact the DNS provider and UKC Support before making repeated changes.

Nominet can publish more than one DS record for a domain, which supports controlled key changes. Most customers should use only the records their DNS provider explicitly supplies.

Common questions

Which domains can I manage through this UKC feature?

The DNSSEC Setup tab is available to the authenticated owner of an eligible active .UK namespace domain managed through UKC’s Nominet registrar connection. This includes names such as .uk, .co.uk and .org.uk. Domains using another registrar connection may not show the tab.

Does DNSSEC replace my SSL certificate?

No. DNSSEC authenticates DNS answers. An SSL certificate and HTTPS encrypt the connection between a visitor and the website. A secure site can and often should use both.

Can UKC create the DS record for me?

No. The DNS provider currently signing your domain must generate and maintain the keys, then supply the exact DS values. UKC publishes the values you provide to Nominet.

Will the change be instant?

The registry state can update quickly, but DNS caches and validation results may take time to refresh. Avoid repeated changes while an earlier update is still propagating.

What if I use UKC DNS but have no DS values?

Do not add a record. The presence of a DNSSEC form does not mean the zone is already signed. Only publish values supplied by the service that is actively signing your DNS.

Why can a wrong DS record break the domain?

A validating resolver expects the signed DNS key to match the DS record in the .UK parent zone. If they do not match, validation fails and the resolver can return an error instead of the website or mail destination.

Ready to manage an existing DS record?

Open the domain and check the live Nominet state first

Only add, change or remove DS records using the exact instructions from the DNS provider signing the domain.

Was this helpful?