Skip to main content

IT security

What is DNSSEC?

DNSSEC cryptographically signs your DNS responses so forged lookups can be detected. See how the chain of trust works, and what it does not protect against.

In short

DNSSEC (Domain Name System Security Extensions) is an extension of DNS that signs DNS responses with digital signatures, so the recipient can verify that the response is genuine and unaltered.

Ordinary DNS has no built-in security: an attacker who can forge a DNS response can send users to a fake server without anyone noticing. With DNSSEC, each zone is signed with a key pair, and trust is built as an unbroken chain from the internet's signed root zone through the top-level domain, for example .dk, down to your own records.

Validating DNS resolvers reject responses where the signature does not match. It is important to understand what DNSSEC does not do: responses are signed but not encrypted, so DNSSEC is about authenticity, not confidentiality. Denmark is among the countries where DNSSEC is most widely adopted, and the .dk zone has been signed for many years. MI Support IT enables and operates DNSSEC as part of customers' DNS and IT security.

Back to the glossary

What is DNSSEC?

DNSSEC (Domain Name System Security Extensions) adds the one thing DNS was never born with: proof that the response is genuine. Each zone is signed with a cryptographic key pair, and every DNS response is accompanied by a digital signature that validating resolvers check. If the signature does not match (because someone has tampered with the response along the way), it is rejected, and the user never reaches the fake server.

Without DNSSEC, DNS lookups are pure declarations of trust: whoever answers first and most convincingly wins. That is exploited in cache poisoning and spoofing attacks, where forged responses send users to the attacker's copy of a legitimate service.

The chain of trust: from the root zone to your domain

The strength of DNSSEC is that trust does not have to be agreed bilaterally. It is inherited through an unbroken chain of signatures:

  1. The root zone at the top of the DNS hierarchy is signed (it has been since 2010). The root zone's key is the world's most closely guarded DNS secret and is handled at public, supervised key ceremonies at IANA.
  2. The top-level domain (e.g. .dk) is signed, and its key is approved by the root zone via a DS record.
  3. Your zone is signed with your key pair, and a DS record at the registry (for .dk: Punktum dk) binds your key into the chain.

A validating resolver can therefore work its way from a root it trusts all the way down to your A, MX or TXT record, and detect any break along the way. Denmark, incidentally, is among the countries in the world where DNSSEC signing of domains is most widespread.

What DNSSEC does not protect against

Three important limitations, so expectations are set correctly:

  • No encryption: DNSSEC signs responses but does not hide them. Confidentiality in lookups requires DNS over HTTPS/TLS, a different tool for a different problem.
  • No protection of the administration itself: If an attacker takes over your DNS account, they can change records and, in many cases, keys too. Access control and MFA on the registrar account remain the foundation.
  • No content control: DNSSEC guarantees that you get the genuine response, not that the server behind the response is benign. Protection of the connection itself is delivered by TLS and certificates.

DNSSEC in practice for Danish businesses

For most, activation is straightforward: many Danish DNS providers and registrars offer DNSSEC as an add-on, where signing and key rotation happen automatically. The pitfall is operation over time: especially changing DNS provider, where the DS record must be handled in the right order, otherwise the entire domain fails validation, and website and email become unavailable to everyone behind validating resolvers. Signed zones are, in other words, more secure but also less forgiving of sloppiness, one more reason DNS should be operated, not just "set up".

How MI Support IT can help

We enable and operate DNSSEC for customers' domains, handle keys and DS records correctly during migrations and keep the entire DNS setup documented, as part of your DNS administration and overall IT security. Contact us if your domain still responds unsigned.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.