Glossary

What is DNSSEC?

Signs your DNS records so resolvers can detect forged or tampered answers.

Written by the SkyQon engineering team · Last verified 4 August 2026

Why it matters

DNS answers are trusted implicitly by everything downstream — mail routing, certificate issuance, your website. DNSSEC signs those answers so a validating resolver can tell a genuine record from one forged or injected along the path.

The standard

RFC 4033, RFC 4034 and RFC 4035 (2005). The zone is signed (RRSIG records), keys are published (DNSKEY), and a DS record held at the parent registry links your zone into the global chain of trust.

Official text: RFC 4033

How it fails

When DNSSEC breaks, it breaks completely. Signatures carry an expiry; if resigning stops, validating resolvers stop answering for your domain at all. The other classic is a key rollover where the DS record at the registrar is never updated to match the new key, breaking the chain one level up where your own monitoring cannot see it.

Related terms

Check this on your own domain

SkyQon reads the same public signals described on this page and scores them for your domain. No account, no agent, nothing to install — a scored report by email in minutes.