One-click DNSSEC — no manual key management
Enable DNSSEC from your control panel in seconds. We generate keys, sign your zone, publish DS records to the registry, and rotate keys automatically — forever.
What is DNSSEC and why does it matter?
The Domain Name System was designed in the 1980s without authentication. Any resolver or network device along the path can forge a DNS response and redirect your users to a malicious server — a technique known as DNS cache poisoning.
DNSSEC solves this by adding a cryptographic chain of trust from the DNS root down to your individual records. Every response is signed; resolvers that support DNSSEC validate the signature before returning the result to the client.
If a signature is missing or invalid, the resolver returns SERVFAIL — protecting users from being silently redirected to a phishing or malware site.
Chain of Trust
DNS Root
Root KSK signs TLD zone
.com TLD
Registry DS record
yourdomain.com
Zone-signing key (ZSK)
DNS Record
RRSIG signature on each record
Each level signs the level below it — break any link and validation fails.
How it works
We handle the complexity so you don't have to
Traditional DNSSEC requires generating key pairs, publishing DS records at the registry, monitoring key expiry, and performing manual rollovers. We automate all of it.
Toggle on in the control panel
One switch in your DNS settings. No CLI, no key generation commands, no registry portal login required.
We sign your zone instantly
Keys are generated in our HSM-backed infrastructure, your zone is signed, and DS records are published to the registry within seconds.
Automatic key rotation — forever
ZSK and KSK rollovers happen on schedule with RFC 5011 automated trust anchor updates. You will never touch a key again.
Algorithms
Supported signing algorithms
We support both modern elliptic-curve and traditional RSA signing. ECDSAP256SHA256 is our default and recommended choice.
ECDSAP256SHA256
Algorithm 13
Elliptic-curve signing offering equivalent security to RSA-2048 at a fraction of the key size. Faster validation, smaller DNS responses.
RSASHA256
Algorithm 8
Traditional RSA 2048-bit signing with SHA-256 hashing. Widely supported across all resolver implementations and registrars.
TLD support
DNSSEC-supported TLDs
DNSSEC availability depends on registry support. Here is the status for our most popular extensions.
| TLD | Registry | DNSSEC |
|---|---|---|
| .com | Verisign | ✓ Supported |
| .net | Verisign | ✓ Supported |
| .org | PIR | ✓ Supported |
| .io | Identity Digital | ✓ Supported |
| .co | Identity Digital | ✓ Supported |
| .app | Google Registry | ✓ Supported |
| .dev | Google Registry | ✓ Supported |
| .cloud | Identity Digital | ✓ Supported |
| .tech | Radix | ✓ Supported |
| .ai | Anguilla NIC | ✓ Supported |
| .au | auDA | ✓ Supported |
| .uk | Nominet | Registry pending |
FAQ
Common DNSSEC questions
What is DNSSEC?
DNSSEC (Domain Name System Security Extensions) adds cryptographic signatures to DNS records. Resolvers that support DNSSEC can verify that a response genuinely came from your authoritative nameserver and has not been tampered with in transit — protecting against cache poisoning and man-in-the-middle attacks.
Do I need DNSSEC?
If you run services where impersonation or DNS hijacking would be harmful — email, banking, e-commerce, government portals — yes. DNSSEC is also increasingly required by regulated industries and some government tender frameworks. For personal or low-risk domains it is still good practice and costs nothing to enable.
Does DNSSEC slow down DNS resolution?
The overhead is minimal. DNSSEC validation adds a small amount of cryptographic work at the resolver, and responses are slightly larger due to the embedded signatures. In practice the latency increase is under 1ms for most queries, which is imperceptible to users.
Which TLDs support DNSSEC?
All major TLDs support DNSSEC. Our supported TLD table below lists every extension we offer together with its DNSSEC status. If a TLD is not in the DNSSEC column, the registry does not yet accept DS records — this is a registry limitation, not an Airfree limitation.
Enable DNSSEC in one click
Log in to your Airfree Clouds control panel and toggle DNSSEC on. That is genuinely all there is to it.