Enable DNSSEC

To enable DNSSEC in DNSimple, open the DNSSEC tab for your domain and follow the configuration wizard. DNSimple signs the zone automatically and, for domains registered with DNSimple, provisions the DS record at the registry with no additional steps required.

If you are new to DNSSEC, start with What Is DNSSEC? to understand what DNSSEC is and how it works. For a comprehensive overview of DNSSEC at DNSimple, see DNS Security Extensions (DNSSEC) at DNSimple.

Prerequisites

Enable DNSSEC

  1. Use the account switcher at the top of the page to select the appropriate account.
    screenshot of switching accounts
  2. In your Domain Names list, click the name of the domain you want to enable DNSSEC on.
    screenshot of list of domain names
  3. Click the DNSSEC tab on the left side.
    screenshot of dnssec in the navigation
  4. On the Configure DNSSEC card, click Configure.
    screenshot of disabled dnssec for a domain
  5. Follow the wizard instructions

Note

To see how to enable DNSSEC with the API, check out our developer documentation.

What Happens Next?

If the domain is registered with DNSimple:

  • The zone will be signed automatically.
  • The DS record will be provisioned directly at the registry. No additional action is needed.

If the domain is registered elsewhere:

  • The zone will be signed automatically.
  • You will receive an email containing the DS record in both DS-data and KEY-data format. Follow its instructions to provision the record with your domain’s registrar. Keep the email until the DS record is live.
  • The DNSSEC tab shows a summary of your active key set: algorithm, key tag, creation date, and next scheduled rotation. It does not display the full DS record during initial setup. Use the values from the email.

Warning

The email includes a deadline for provisioning the DS record. If the DS record is not in place at your registrar by that date, DNSSEC is disabled on the domain.

Troubleshooting

If you encounter issues after enabling DNSSEC, see Troubleshoot DNSSEC for comprehensive guidance on diagnosing and resolving common DNSSEC problems.

Have more questions?

If you have any questions or need assistance enabling DNSSEC, contact support, and we’ll be happy to help.