DNSSEC
DNSSEC verifies data using cryptographically secured signatures that are calculated based on the data to be protected and transmitted to the client along with the data. The signature can be used to verify whether the data was sent by an authorized source. At the same time, the signature makes it possible to verify whether the data was altered during transmission.
Requirements for Enabling DNSSEC
To use DNSSEC, the following requirements must be met:
- DNSSEC support at the TLD level (e.g.,
.de) - DNSSEC support from the DNS provider
Automatic Configuration
For DNSSEC to be activated automatically, both the DNS zone and the domain must be managed via creoline. The following requirements must be met for automatic configuration:
- DNSSEC must be disabled for the domain
- DNSSEC must be disabled for the DNS zone
- The domain must have been registered through creoline
- The DNS zone must be managed via creoline
- The domain’s nameservers must point to the default creoline nameservers
Navigate to the DNS zone for which you want to enable DNSSEC and click Settings → Enable DNSSEC.
In the pop-up window, you can specify the mode in which DNSSEC should be enabled.
| Mode | Description |
|---|---|
| Configure Automatically | In this mode, the DNSSEC configuration is automatically stored with the corresponding domain, so no further steps are required to enable DNSSEC. |
| Generate DNSSEC Configuration Only | In this mode, the associated domain is not automatically updated, and the DNSSEC configuration must be manually added to the domain. |
Caution: Before enabling DNSSEC, verify that your domain provider supports the DNSSEC protocol. If your domain is registered through creoline, the DNSSEC option will only be displayed if the DNSSEC protocol is supported by the corresponding TLD.
Manual Configuration
Navigate to the DNS zone for which you want to enable DNSSEC and click Settings → Enable DNSSEC.
Select the Generate DNSSEC Configuration Only mode so that the DNSSEC configuration is not automatically stored with the domain.
Click the DNSSEC button to view the current DNSSEC configuration.
Register the DNSKEY record
257 KSK with your domain provider to fully sign the DNS zone. The DNSKEY record of Type 256 ZSK does not need to be registered with your domain provider.