Understand and manage DNSSEC
Coordinate signed DNS records with your registrar so validation remains consistent.
Where Tools → Domains → Zone Editor → DNSSEC
Before you start
- Confirm cPanel hosts authoritative DNS and your registrar supports the required DS records.
- Ask support for help if you are changing nameservers or replacing existing DNSSEC keys.
Steps
-
1
Review whether keys already exist before generating a new one. Do not rotate or remove keys as routine cleanup.
-
2
For a new deployment, use the key-creation controls offered and obtain the DS information that corresponds to that exact key.
-
3
Publish the matching DS record at the domain registrar using its DNSSEC controls. A DNS record inside the zone is not a substitute for the registrar’s delegation data.
-
4
Validate the chain of trust before considering the setup complete. For disablement, migration or rotation, coordinate the order and timing with your DNS provider and registrar.
-
5
Open Zone Editor and find your domain. Click its DNSSEC button, separate from Manage.
DNSSEC has its own button beside each domain.
Check it worked
- Use your provider’s DNSSEC validation method to confirm the public domain resolves with a valid chain.
- If validating resolvers stop resolving the domain, contact support with the current key and DS details rather than blindly generating more keys.