Skip to main content
← Back to Help CentreDNS Configuration

Enabling DNSSEC for your domain

DNSSEC digitally signs your DNS records to protect against spoofing and cache poisoning. Enable it in one click and verify the chain of trust.

DNSSEC signs your DNS records so resolvers can verify the answers they receive are genuine, closing the door on DNS spoofing and cache-poisoning attacks. On Airfree Clouds it is a single toggle.

Turn it on

  • Open the domain and go to DNS → DNSSEC.
  • Toggle DNSSEC on — we generate the keys and publish the DS record automatically.
  • For a domain registered elsewhere, paste the DS record we show into your registrar once.

Verify the chain of trust

The DNSSEC page shows Verified once the parent registry has published your DS record — usually within minutes, occasionally a few hours. A public DNSSEC analyser should then report an unbroken chain from the root zone to yours.

If the chain shows as broken right after enabling, wait for the registry to publish the DS record before troubleshooting.

Did this help?

If you still need a hand, our support team usually replies within a few hours.

Contact support →