Skip to content
FI
Domains 7 min read · Updated 08/2026

DNS settings and DNSSEC for your business

DNS connects your domain to the services customers use. A mistaken record can interrupt your website or email; an incorrectly configured DNSSEC chain can make otherwise correct records fail validation. Treat both as part of your production infrastructure.

DNSSEC adds authenticity and integrity checks to DNS data. It helps a validating resolver detect forged answers. It does not encrypt DNS traffic, secure your WordPress installation or replace an HTTPS certificate. These protections address different parts of the connection.

Know which company controls the records

Your registrar manages the domain registration. Your authoritative DNS provider publishes its records. Your web host serves the website, and your email provider receives messages. One supplier may perform all four roles, but changing one service does not automatically move the others.

Before editing anything, record the current nameservers and export or save the DNS zone. Confirm which account has authority to change it. If several suppliers are involved, name the person coordinating the change. The DNS basics guide explains how these roles fit together.

Check the records your business relies on

Record Purpose Check before changing it
A / AAAA Connect a hostname to an IP address The destination serves the correct website
CNAME Alias one hostname to another The external service recognises your hostname
MX Route incoming email Every listed destination belongs to the intended mail setup
TXT Publish verification and policy data Existing email and service records are preserved
CAA Restrict certificate issuance Your certificate provider remains authorised
DS Link DNSSEC trust from the parent zone It matches the active signing configuration

Email authentication commonly uses TXT records, though a provider may ask for CNAME records for DKIM. Use the actual instructions for your service, rather than copying another company's values.

What DNSSEC validates

A signed zone publishes cryptographic signatures and public key information. A validating resolver checks these against a chain of trust linked through the parent zone. The parent-side DS record is an essential connection in that chain.

If signatures or keys no longer match, validation can fail and users may receive a DNS error. That is why enabling DNSSEC is more than adding an arbitrary TXT record. Cloudflare's DNSSEC documentation describes the signing and registrar steps for its service; other providers have their own workflow.

DNSSEC does not authenticate the content of a website. A compromised legitimate server can still deliver harmful content through correctly signed DNS. Keep website security and certificate management in the same maintenance plan.

Enable it in a controlled sequence

  1. Confirm that your DNS provider and registrar support DNSSEC for your domain extension.
  2. Check whether signing and the DS record are already active. Avoid creating a second, conflicting setup.
  3. Follow the provider's procedure to enable signing and obtain the required parent-zone information.
  4. Publish or authorise the DS record through the registrar if this is not automated.
  5. Validate the complete chain, then test the website and email through normal client connections.

Keep a record of who manages key changes and what happens during a future provider migration. Do not manually rotate keys without the corresponding parent-zone procedure.

Plan nameserver changes carefully

Copy the full zone to the new DNS provider before changing delegation. Include mail records, verification records, subdomains and less frequently used integrations. A working homepage does not prove the zone is complete.

DNSSEC migration needs a plan that matches both providers. A stale DS record referring to old signing keys can cause an outage. Do not simply change nameservers and assume the signing chain follows. Ask the providers to coordinate the sequence and validate it afterwards.

TTL values influence how long cached answers remain usable. Lowering a TTL helps planned changes only after previously cached values expire. It does not instantly refresh every resolver on the internet.

Keep email protection separate

SPF, DKIM and DMARC address sender authentication. Transport policies such as MTA-STS address supported mail-server connections. Neither is a substitute for DNSSEC, and DNSSEC does not turn either on automatically.

For routine operations, keep a small change log containing the reason, previous value, new value, responsible person and verification result. ResaHost's domain management service can help bring these responsibilities together without leaving the business owner to coordinate an unexplained DNS error.

Read next

Domains

Choose an Available Domain Name for Your Business

Read guide →
Domains

What Is a Domain Name? A Guide for Business Owners

Read guide →

Cookie settings

The English website does not load optional analytics or marketing tags. There are no optional cookies to choose here.

Read our cookie information for details about necessary website functionality and external services.

Read the cookie information