Turn on DNSSEC
Sign your domain's DNS so answers cannot be forged, and add the DS record at your registrar only when it is safe to do so.
DNSSEC signs your domain's DNS answers, so resolvers that check signatures can tell if an answer has been tampered with. It takes two steps: lbreeze signs the zone, then a DS record at your domain's registrar tells the world to expect signatures. The order matters, and the control panel enforces it.
Step 1: sign the zone
- In your control panel, choose DNS zones and click your domain.
- Find the DNSSEC card and click Enable DNSSEC.
lbreeze creates the signing keys and signs the zone on the next update. Signatures are renewed automatically before they expire.
Step 2: add the DS record at your registrar
The DS record does not appear straight away. The card shows it only once every one of our nameservers has been checked and is serving your zone signed, with the key the DS record names. Until then, the card lists each nameserver and what it is serving, so you can see what is still being waited for.
When it is ready, the card shows the DS record and a Copy DS record button. It looks like this:
12345 13 2 9f86d081884c7d659a2feaa0c55ad015...
The four parts are the key tag, the algorithm (13, ECDSA P-256 with SHA-256), the digest type (2, SHA-256) and the digest.
If your domain is registered with lbreeze:
- In your client area, go to Domains and click Manage beside the domain.
- Open the DNSSEC tab and click Add DS record.
- Enter the Key tag, choose Algorithm 13 and Digest type 2, and paste the Digest (hex).
- Click Save DNSSEC.
If it is registered elsewhere, paste the same values into your registrar's DNSSEC or DS record form.
Good to know: If the card ever shows Serving unsigned, do not publish the DS record, and remove it at your registrar if it is already there. While a DS record is published and the zone is not signed, resolvers that check signatures cannot reach your domain at all.
What else changes
- When the zone is signed, lbreeze also publishes a DANE record for your mail server's certificate and keeps it in step when the certificate renews.
- ALIAS records cannot be used in a signed zone.
Change the keys
- Rotate ZSK (one step) replaces the key that signs the records. It is done in three steps, one click each, and the zone stays valid throughout. Nothing changes at the registrar.
- Rotate KSK replaces the key the DS record points at. The card then shows a pending DS record: replace the DS at your registrar with it, wait for that to be published, then click DS is live — complete rotation.
Turn DNSSEC off safely
- Remove the DS record at your registrar first.
- Wait for the DS record's TTL to pass.
- Click Disable DNSSEC on the DNSSEC card and confirm.
lbreeze checks your registrar's side and refuses while the DS record is still published, because switching signing off under a published DS record takes the whole domain offline. If you have removed it and the check has not caught up, tick I have removed the DS at the registrar; switch off even if the parent still shows it. Turning DNSSEC off also removes the DANE records.
Related
More in Domains and DNS
- Point your domain at lbreeze
Make your domain reach your lbreeze website and email, either by switching its nameservers or by adding records where your DNS lives now.
- Edit your DNS records
Add, change and delete DNS records for a domain hosted with lbreeze, including MX, TXT, SRV and CAA records, or import a whole zone file.
- Undo DNS changes with zone history
Go back to an earlier version of your DNS records, keep a copy before a risky change, download your zone, or bring back a deleted domain.
- Lower the TTL before moving a domain
Shorten how long the world remembers your DNS records a day before a move, so the switch takes minutes instead of hours.

