DNSSEC for .UK domains
DNSSEC helps prove that DNS answers are authentic
DNSSEC digitally signs DNS data so compatible networks can detect altered or forged answers. It does not encrypt website traffic or replace an SSL certificate. For eligible .UK domains, UKC lets the account owner publish and manage the exact DS records supplied by the DNS provider that signs the domain.
How does DNSSEC work?
Normal DNS translates names such as yourdomain.co.uk into the addresses used by websites and email. DNSSEC adds digital signatures that allow a validating resolver to check that a DNS answer came from the expected source and was not changed in transit.
1. Your DNS provider signs the zone
The provider hosting your DNS creates and maintains cryptographic keys, then signs the domain’s DNS records.
2. The provider supplies DS values
It gives you a key tag, algorithm, digest type and digest that identify the signed key.
3. You publish the DS at Nominet
For an eligible UKC-managed .UK domain, enter those exact values in the Client Area. UKC sends the DS record to the .UK registry.
4. Resolvers validate the chain
Compatible resolvers follow the signed chain from the .UK parent zone to your domain and reject answers that fail validation.
Who should use DNSSEC?
DNSSEC is useful when the DNS provider actively supports zone signing and can supply and maintain the correct DS information.
Consider using it
Your business relies on its domain, your DNS provider supports DNSSEC and you want stronger protection against forged DNS answers.
Good for managed DNS
Your specialist DNS provider signs the zone, displays the DS values and gives clear instructions for key changes.
Use it with a maintenance plan
You or your provider can coordinate nameserver changes, DNS provider moves and key rollovers without leaving a stale DS record.
Do not enable it blindly
Do not invent DS values or add them before the DNS zone is signed. If the provider does not offer DNSSEC, there is nothing valid to publish.
What does DNSSEC protect?
| Security need | Does DNSSEC help? | What else is needed? |
|---|---|---|
| Detect forged or altered DNS answers | Yes | The DNS zone must be signed and the DS record must be correct |
| Prove DNS data came from the expected signed zone | Yes | A validating resolver must perform the checks |
| Encrypt website traffic | No | Use HTTPS with a valid SSL certificate |
| Encrypt email connections | No | Use the secure IMAP and SMTP settings supplied for the mailbox |
| Remove malware or secure a compromised website | No | Use website security, updates, backups and malware protection |
How do I add a DS record in the UKC Client Area?
The DNS provider that signs your zone must give you the values first. Copy them exactly and do not convert or shorten the digest.
- 1Enable signing at the DNS provider
Follow the provider’s DNSSEC setup. Wait until it confirms that the domain’s DNS zone is signed and shows the DS record.
- 2Open DNSSEC Setup
Sign in to the UKC Client Area, open My Domains, choose the eligible .UK domain and select DNSSEC Setup.
- 3Copy all four values exactly
Enter the key tag, algorithm, digest type and digest supplied by the DNS provider. Review every character before continuing.
- 4Confirm and verify
Review the proposed registry change, type the domain when asked and submit it. Reopen the tab to confirm the DS record shown by Nominet matches the provider.
What are the four DS record fields?
| Field | Meaning | What to enter |
|---|---|---|
| Key tag | A short numeric identifier for the DNSSEC key | Copy the number supplied by the DNS provider |
| Algorithm | The code for the signing algorithm | Select the exact algorithm number supplied |
| Digest type | The code for the method used to create the digest | Select the exact digest type supplied |
| Digest | The long hexadecimal fingerprint of the key | Paste the complete value with no spaces |
How should I change or remove DS records?
Key rollover
Follow the DNS provider’s sequence. A rollover can temporarily require both the old and new DS records. Remove the old record only when the provider says it is safe.
Changing DNS provider
Coordinate signing, nameservers and DS records as one migration. Do not leave a DS record pointing to keys that the new provider does not use.
Turning DNSSEC off
Use the provider’s secure transition process. Do not stop signing while a valid DS record is still expected by cached resolvers.
Recovering from an error
Compare the live registry record with the provider’s current values. If the website or email is failing, contact the DNS provider and UKC Support before making repeated changes.
Nominet can publish more than one DS record for a domain, which supports controlled key changes. Most customers should use only the records their DNS provider explicitly supplies.
Common questions
Which domains can I manage through this UKC feature?
The DNSSEC Setup tab is available to the authenticated owner of an eligible active .UK namespace domain managed through UKC’s Nominet registrar connection. This includes names such as .uk, .co.uk and .org.uk. Domains using another registrar connection may not show the tab.
Does DNSSEC replace my SSL certificate?
No. DNSSEC authenticates DNS answers. An SSL certificate and HTTPS encrypt the connection between a visitor and the website. A secure site can and often should use both.
Can UKC create the DS record for me?
No. The DNS provider currently signing your domain must generate and maintain the keys, then supply the exact DS values. UKC publishes the values you provide to Nominet.
Will the change be instant?
The registry state can update quickly, but DNS caches and validation results may take time to refresh. Avoid repeated changes while an earlier update is still propagating.
What if I use UKC DNS but have no DS values?
Do not add a record. The presence of a DNSSEC form does not mean the zone is already signed. Only publish values supplied by the service that is actively signing your DNS.
Why can a wrong DS record break the domain?
A validating resolver expects the signed DNS key to match the DS record in the .UK parent zone. If they do not match, validation fails and the resolver can return an error instead of the website or mail destination.
Ready to manage an existing DS record?
Open the domain and check the live Nominet state first
Only add, change or remove DS records using the exact instructions from the DNS provider signing the domain.