How to enable / disable DNSSEC

Enable DNSSEC

You can quickly and easily enable DNSSEC on your domains installed on our NS, directly on your customer portal:

  1. Log in to your account
  2. Access your domain portfolio: go to the "Domains > Portfolio" menu item
  3. Select the domain(s) for which you want to enable DNSSEC
  4. In the bottom bar, click on DNSSEC and then on "⊕ Enable DNSSEC"
  5. Finished! Please wait 24-48 hours for DNSSEC to be activated.

 

Domains > Portfolio > Select domain > DNSSEC

 

Using external name servers

If you want to enable DNSSEC for a domain name registered with us but technically managed by an external DNS provider, you can follow the procedure above—setting up a DNS zone on our name servers if necessary (this will have no impact). DNSKEYs can be added or modified directly via the BrandShelter portal.

Alternatively, you can contact our Customer Care Service at support@brandshelter.com, or reach out to your account manager if you have one.

After completing the necessary steps with your DNS management provider to request DNSSEC activation and retrieve the DNSKEY information, please provide us with the required data as follows:

DS 8997 13 2 e8lkcjRZvJorYc5NpRbv10xzxHZ6G0v2Vwg+5sfLlOfWk4WoFlO1A==

and

Key tag: 
Algorithm:
Flags: 
Digest algorithm: 
Digest algorithm type: 
Digest: 
Signing algorithm: 
Signing algorithm type: 
Public key: 
DS record:

 

Important note:

• In the event of DNSSEC key changes or renewals (key rollovers), you must submit an update request to us; any modification to DNSKEYs requires an explicit request if external name servers are used.

• If the DNSKEYs have an expiration date and external name servers are used, you must periodically provide us with the updated information regarding the DNSKEYs and/or DS records.

• We recommend monitoring the validity of DNSKEYs and paying close attention to key renewals.

• Management must be handled on a domain-by-domain basis; no bulk update functionality is available. Furthermore, changes are not applied instantly and require propagation time.

 

 

Disable DNSSEC

To disable DNSSEC, follow the same steps and procedure.

In the bottom bar, click on DNSSEC and then on "🗑️ Disable DNSSEC". If you get the message: "Unable to disable DNSSEC on these domains:" then, the DNSSEC is probably already disabled for your domain(s). You can check DNSSEC activation here:  https://dnssec-analyzer.verisignlabs.com/  or here: https://zonemaster.net/en/

 

Important:

  1. DNSSEC activation/deactivation for BrandShelter domains typically requires 24 hours (to 48 hours) between zone signing and the modification of the domain.
    For specific TLDs, activation times vary:
    .CH / .LI: Changes are activated after 3 days.
    .SK: Parent updates take 72 hours.
    .CZ: Parent updates take 7 days.
     
  2. We always recommend to wait at least 48 hours after disabling DNSSEC before enabling it again. Some DNS caches may still have old DNS keys cached even if their TTL has already expired.
    Standard practice for migrations/transfers involves deactivating DNSSEC and waiting 24 to 48 hours to allow DNS caches to catch up before reactivation.
     
  3. DNSSEC is not supported and cannot be activated on all extensions / TLDs, some registries / TLDs are not compatible.
    BrandShelter - List of TLDs supporting DNSSEC
    ICANN - List of TLDs supporting DNSSEC
     
  4. Certain types of DNS records are not supported for DNSSEC-signed zones. For example, the use of APEX ALIAS records is not supported for DNSSEC-signed zones, and in the worst-case scenario, this will compromise the DNSSEC security of the zone.
     
  5. Is there any risk associated with using DNSSEC with external name servers (NS), and if so, what is the level of risk? As long as DNS zones remain hosted on your own DNS infrastructure and the published DNSSEC information exactly matches the zone configuration, the risk level can be considered low. However, it is important to note that DNSSEC introduces an additional layer of operational complexity. Configuration errors, inadequate key rollover management, or inconsistencies between information published at the registry level and data on the DNS servers can lead to DNS resolution issues. This is a genuine risk to consider for DNSSEC-secured domains hosted on external name servers.
     
  6. Is maintenance required after activation for domains using external name servers? Yes. The main area requiring attention is DNSSEC key management and potential key rollover operations. Whenever DNSKEYs are renewed or replaced, the associated information must be updated to maintain the DNSSEC chain of trust. It is therefore recommended to regularly monitor key validity.
     
  7. Do DNSKEY updates need to be requested from or communicated to BrandShelter? This depends on the DNS infrastructure being used. When DNS zones are hosted on BrandShelter's DNS infrastructure, DNSSEC management is automated, and no action is required on your part for routine operations. When DNS zones are hosted on external DNS servers, manual maintenance is required; any changes to DNSKEYs must be accounted for and communicated to our team to maintain the DNSSEC chain of trust. In this latter scenario—using external name servers—no automated update mechanism is available.
     
  8. DNSSEC introduces an additional layer of operational complexity. The primary challenge generally lies not in the initial activation, but rather in the ongoing management of the DNSSEC key lifecycle, including key rollovers and updates to associated DNSSEC information. Mismanagement of these operations can lead to DNS resolution issues and even render a domain inaccessible to resolving servers that perform DNSSEC validation; this is a genuine risk that must be considered. Monitoring the validity of DNSKEYs and proactively managing key rollover operations are key operational priorities when DNS zones are hosted on external DNS infrastructure. While these considerations certainly do not diminish the security benefits of DNSSEC, they must be factored into any assessment of the cost-benefit ratio and the long-term operational processes associated with DNSSEC.