Skip to main content
← Back to BlogSecurity

DNSSEC explained: why every domain needs it and how to enable it in 60 seconds

Jane Smith8 min read

The Domain Name System is the address book of the internet: it turns a name like example.com into the IP address your browser actually connects to. The problem is that classic DNS was designed in an era of implicit trust — a resolver simply believes the answer it receives. DNSSEC closes that gap by letting every answer be cryptographically verified.

What DNS spoofing actually does

In a spoofing or cache-poisoning attack, an attacker convinces a resolver to cache a forged answer. A visitor who types your domain is then quietly sent to a server the attacker controls — a convincing clone that harvests logins, payment details, or session cookies. Because the browser bar still shows your real domain, most people never notice.

How DNSSEC establishes trust

DNSSEC signs each DNS record with a private key. Resolvers fetch the matching public key and verify the signature, building an unbroken chain of trust from the root zone down to your domain. If any record has been tampered with, the signature fails and the resolver discards the answer instead of serving a forgery.

  • Each zone is signed with a Zone Signing Key (ZSK).
  • The ZSK is vouched for by a Key Signing Key (KSK).
  • A DS record in the parent zone links your domain into the global chain of trust.

Enabling it on Airfree Clouds

Airfree Clouds manages the entire key lifecycle for you — generation, signing, rotation, and the DS record handed to the registry. For domains registered with us, there is nothing to copy or paste.

  • Open the domain in your dashboard and go to the DNS tab.
  • Toggle DNSSEC on — we generate the keys and publish the DS record automatically.
  • Wait for the registry to reflect the DS record (usually minutes, occasionally a few hours).
For a domain registered elsewhere but using Airfree DNS, we still generate the keys — you paste the DS record we show you into your registrar once.

Verifying the chain of trust

After enabling, the DNS tab shows the chain as Verified once the parent registry has published your DS record. You can cross-check with any public DNSSEC analyser: a valid setup returns a green, unbroken chain from the root to your zone. If it reports a broken chain immediately after enabling, wait for propagation before troubleshooting.

Ready to get started?

Register a domain, set up business email, and manage DNS — all in one place, privacy-first.

Search domains →