Skip to main content
Security

One-click DNSSEC — no manual key management

Enable DNSSEC from your control panel in seconds. We generate keys, sign your zone, publish DS records to the registry, and rotate keys automatically — forever.

Explainer

What is DNSSEC and why does it matter?

The Domain Name System was designed in the 1980s without authentication. Any resolver or network device along the path can forge a DNS response and redirect your users to a malicious server — a technique known as DNS cache poisoning.

DNSSEC solves this by adding a cryptographic chain of trust from the DNS root down to your individual records. Every response is signed; resolvers that support DNSSEC validate the signature before returning the result to the client.

If a signature is missing or invalid, the resolver returns SERVFAIL — protecting users from being silently redirected to a phishing or malware site.

Chain of Trust

DNS Root

Root KSK signs TLD zone

.com TLD

Registry DS record

yourdomain.com

Zone-signing key (ZSK)

DNS Record

RRSIG signature on each record

Each level signs the level below it — break any link and validation fails.

How it works

We handle the complexity so you don't have to

Traditional DNSSEC requires generating key pairs, publishing DS records at the registry, monitoring key expiry, and performing manual rollovers. We automate all of it.

1

Toggle on in the control panel

One switch in your DNS settings. No CLI, no key generation commands, no registry portal login required.

2

We sign your zone instantly

Keys are generated in our HSM-backed infrastructure, your zone is signed, and DS records are published to the registry within seconds.

3

Automatic key rotation — forever

ZSK and KSK rollovers happen on schedule with RFC 5011 automated trust anchor updates. You will never touch a key again.

Algorithms

Supported signing algorithms

We support both modern elliptic-curve and traditional RSA signing. ECDSAP256SHA256 is our default and recommended choice.

ECDSAP256SHA256

Algorithm 13

Recommended

Elliptic-curve signing offering equivalent security to RSA-2048 at a fraction of the key size. Faster validation, smaller DNS responses.

RSASHA256

Algorithm 8

Traditional RSA 2048-bit signing with SHA-256 hashing. Widely supported across all resolver implementations and registrars.

TLD support

DNSSEC-supported TLDs

DNSSEC availability depends on registry support. Here is the status for our most popular extensions.

TLDRegistryDNSSEC
.comVerisign✓ Supported
.netVerisign✓ Supported
.orgPIR✓ Supported
.ioIdentity Digital✓ Supported
.coIdentity Digital✓ Supported
.appGoogle Registry✓ Supported
.devGoogle Registry✓ Supported
.cloudIdentity Digital✓ Supported
.techRadix✓ Supported
.aiAnguilla NIC✓ Supported
.auauDA✓ Supported
.ukNominetRegistry pending

FAQ

Common DNSSEC questions

What is DNSSEC?

DNSSEC (Domain Name System Security Extensions) adds cryptographic signatures to DNS records. Resolvers that support DNSSEC can verify that a response genuinely came from your authoritative nameserver and has not been tampered with in transit — protecting against cache poisoning and man-in-the-middle attacks.

Do I need DNSSEC?

If you run services where impersonation or DNS hijacking would be harmful — email, banking, e-commerce, government portals — yes. DNSSEC is also increasingly required by regulated industries and some government tender frameworks. For personal or low-risk domains it is still good practice and costs nothing to enable.

Does DNSSEC slow down DNS resolution?

The overhead is minimal. DNSSEC validation adds a small amount of cryptographic work at the resolver, and responses are slightly larger due to the embedded signatures. In practice the latency increase is under 1ms for most queries, which is imperceptible to users.

Which TLDs support DNSSEC?

All major TLDs support DNSSEC. Our supported TLD table below lists every extension we offer together with its DNSSEC status. If a TLD is not in the DNSSEC column, the registry does not yet accept DS records — this is a registry limitation, not an Airfree limitation.

Free with every domain

Enable DNSSEC in one click

Log in to your Airfree Clouds control panel and toggle DNSSEC on. That is genuinely all there is to it.