Skip to content

Understand and manage DNSSEC

Coordinate signed DNS records with your registrar so validation remains consistent.

Where Tools → Domains → Zone Editor → DNSSEC

Before you start

  • Confirm cPanel hosts authoritative DNS and your registrar supports the required DS records.
  • Ask support for help if you are changing nameservers or replacing existing DNSSEC keys.

Steps

  1. 1

    Review whether keys already exist before generating a new one. Do not rotate or remove keys as routine cleanup.

  2. 2

    For a new deployment, use the key-creation controls offered and obtain the DS information that corresponds to that exact key.

  3. 3

    Publish the matching DS record at the domain registrar using its DNSSEC controls. A DNS record inside the zone is not a substitute for the registrar’s delegation data.

  4. 4

    Validate the chain of trust before considering the setup complete. For disablement, migration or rotation, coordinate the order and timing with your DNS provider and registrar.

  5. 5

    Open Zone Editor and find your domain. Click its DNSSEC button, separate from Manage.

    DNSSEC has its own button beside each domain.

Check it worked

  • Use your provider’s DNSSEC validation method to confirm the public domain resolves with a valid chain.
  • If validating resolvers stop resolving the domain, contact support with the current key and DS details rather than blindly generating more keys.