What is DNSSEC?
Signs your DNS records so resolvers can detect forged or tampered answers.
Written by the SkyQon engineering team · Last verified 4 August 2026
Why it matters
DNS answers are trusted implicitly by everything downstream — mail routing, certificate issuance, your website. DNSSEC signs those answers so a validating resolver can tell a genuine record from one forged or injected along the path.
The standard
RFC 4033, RFC 4034 and RFC 4035 (2005). The zone is signed (RRSIG records), keys are published (DNSKEY), and a DS record held at the parent registry links your zone into the global chain of trust.
Official text: RFC 4033
How it fails
When DNSSEC breaks, it breaks completely. Signatures carry an expiry; if resigning stops, validating resolvers stop answering for your domain at all. The other classic is a key rollover where the DS record at the registrar is never updated to match the new key, breaking the chain one level up where your own monitoring cannot see it.
Related terms
Check this on your own domain
SkyQon reads the same public signals described on this page and scores them for your domain. No account, no agent, nothing to install — a scored report by email in minutes.