How to Turn On DNSSEC for Your Domain in cPanel

DNSSEC adds a digital signature to your domain's DNS records so that internet resolvers can tell a genuine answer from a forged one. It's a two-part job: you create the signing key in cPanel, then add a matching DS record at your domain registrar. This guide shows you how to turn on DNSSEC for your domain in cPanel, how to add the DS record, how to check it's working -- and how to avoid the one mistake that can take your whole domain offline.

What DNSSEC does (and doesn't do)

Normally, when someone types your domain into a browser, their resolver asks for your records and trusts whatever answer comes back. An attacker who can slip in a fake answer (called DNS spoofing or cache poisoning) could send your visitors or your email somewhere else.

With DNSSEC, our nameservers sign your records, and the registry for your domain extension (such as .com) publishes a fingerprint of your key -- the DS record. Resolvers that check DNSSEC follow that chain of trust from the registry to our nameservers. If a signature doesn't match, they refuse the answer.

  • It does: protect visitors whose resolvers validate DNSSEC (Google Public DNS, Cloudflare's 1.1.1.1 and many internet providers do) from forged DNS answers.
  • It doesn't: encrypt anything, replace your SSL certificate, stop hacking of your website, or speed anything up.

DNSSEC is optional. It's worth turning on if you're comfortable with the steps below and you don't plan to change nameservers soon.

Before you start

  • Your domain must use our nameservers: ns5.instantaccess.net, ns6.instantaccess.net, ns1.fanaticalhosting.com and ns2.fanaticalhosting.com. If your DNS is hosted elsewhere (for example Cloudflare or your registrar's DNS), set up DNSSEC with that provider instead. The cPanel key does nothing there.
  • Your registrar must support DS records for your domain extension. Most registrars do for .com, .net, .org and most country codes. Look for a "DNSSEC" or "DS records" section in their domain settings.
  • Don't plan a nameserver change. If you might move to Cloudflare or another host soon, wait until after the move.

The golden rule: nameservers and DS record must match

Once a DS record is published at the registry, resolvers expect signed answers that match it. If they get answers signed with a different key -- or unsigned answers -- they treat your domain as broken and return an error. Visitors see "This site can't be reached" and email to your domain starts bouncing, even though nothing is wrong with your hosting.

That happens when:

  • You change nameservers (to Cloudflare, another host, or your registrar's DNS) while the old DS record is still at the registrar.
  • You delete or deactivate the key in cPanel while the DS record is still at the registrar.
  • You enter the DS values wrongly at the registrar.

So always remember the order: add the key in cPanel first, then the DS record. When removing DNSSEC: remove the DS record first, wait, then remove the key.

Step 1: Create the DNSSEC key in cPanel

  1. Log in to cPanel (from the client area, Services > My Services, choose your plan, then Log in to cPanel).
  2. Go to Domains > Zone Editor.
  3. Find your domain in the list and click DNSSEC.
  4. Click Create Key. cPanel shows the settings it will use. You can click Customize to change the algorithm or key setup, but the defaults are the right choice for almost everyone.
  5. Confirm by clicking Create. After a moment you'll see a new key listed with its Key Tag, algorithm and status. Make sure it shows as Active.

Which algorithm?

AlgorithmNumberNotes
ECDSA Curve P-256 with SHA-25613Modern, compact and widely supported. A good choice if your registrar lists it.
RSA/SHA-2568The most widely supported option. Choose this if your registrar's DS form doesn't offer algorithm 13.

Before you create the key, glance at your registrar's DNSSEC form to see which algorithm numbers it accepts. If it only lists 8, customize the key to RSA/SHA-256.

Step 2: Copy the DS record details

  1. On the DNSSEC page for your domain, click View DS Records (or open the key's details).
  2. You'll see the values your registrar needs. Leave this page open.
FieldWhat it looks like
Key TagA number, such as 24617
AlgorithmA number, such as 13 or 8
Digest TypeA number: 2 means SHA-256. If several digests are shown, SHA-256 (type 2) is the one to use.
DigestA long string of letters and numbers (64 characters for SHA-256)

Some registrars (and some country-code registries) ask for the public key itself instead of a digest. In that case, copy the public key from the key's details in cPanel.

Step 3: Add the DS record at your registrar

  1. Log in to the company where your domain is registered and open the domain's settings.
  2. Find the DNSSEC or DS Records section and choose to add a record.
  3. Enter the Key Tag, Algorithm, Digest Type and Digest exactly as cPanel shows them. Paste the digest rather than typing it, with no spaces.
  4. Save.

If your domain is registered with us, log in to the client area, go to Domains > My Domains, and open the domain's management page. If you don't see a DNSSEC option there, open a ticket with the four DS values and we'll add them for you.

Step 4: Check it's working

The registry usually publishes the DS record within an hour or so, though it can take longer. Then:

  1. Go to dnsviz.net, enter your domain and run the analysis. A healthy result shows a chain from the root, through your extension (such as .com), down to your domain, with no red errors.
  2. Or, on a Mac or Linux computer, run:
    dig example.com DS +short
    dig example.com A +dnssec
    The first command should return your Key Tag, algorithm, digest type and digest. In the second, look for ad in the flags: line when using a validating resolver such as @1.1.1.1, and for RRSIG records in the answer.
  3. Load your website and send yourself a test email to confirm everything still works.

Online checkers and the commands for Windows are covered in DNS Propagation: Why Domain Changes Take Time and How to Check.

How to turn DNSSEC off safely

Do this before changing nameservers, moving to Cloudflare, or moving your hosting.

  1. Remove the DS record at your registrar and save.
  2. Wait at least 48 hours. Resolvers may still have the old DS record cached. The waiting time depends on the registry, and a day or two covers most of them.
  3. Check that dig example.com DS +short (or DNSViz) no longer shows a DS record.
  4. Only then deactivate or delete the key in cPanel (Domains > Zone Editor > DNSSEC), or change your nameservers.

Troubleshooting

My site shows "This site can't be reached" on some networks but not others

This is the classic DNSSEC failure. Validating resolvers (Google, Cloudflare and many ISPs) reject your domain while non-validating ones still work. Check DNSViz. If it shows a DS record that doesn't match any key, either correct the DS record at the registrar or remove it. Open a ticket if you're not sure which to do -- this is urgent, because email to your domain can bounce too.

dig shows SERVFAIL

Run the same lookup with +cd added (for example dig @8.8.8.8 example.com A +cd), which turns validation off. If that works but the normal lookup fails, the problem is DNSSEC, not your records.

The registrar rejects the DS record

Check the algorithm number is one they support, the digest type is 2, and the digest was pasted without spaces. If the registrar only supports algorithm 8 and your key is 13, delete the key in cPanel (it's safe while no DS record is published), create a new one with RSA/SHA-256, and try again.

I deleted the key by mistake and the DS record is still there

Remove the DS record at the registrar right away, then open a ticket. Your domain will recover once resolvers stop caching the old DS record.

Common questions

Do I need DNSSEC?

It's not required for your website, email or SSL certificate to work. It's an extra layer against a specific kind of attack. Some organizations require it for compliance.

Does DNSSEC affect AutoSSL or email?

When set up correctly, no. When set up wrongly, it can break both, because they depend on DNS answers.

Do I need to renew or rotate the key?

Not on a schedule. The key doesn't expire the way an SSL certificate does. If you ever replace it, add the new DS record at the registrar, wait for it to publish, and only then remove the old key and old DS record.

I use Cloudflare. Should I use cPanel's DNSSEC?

No. When Cloudflare hosts your DNS, turn on DNSSEC in the Cloudflare dashboard and use the DS record it gives you.

Can I still edit records in the Zone Editor?

Yes. Edit records as usual. The server re-signs the zone for you.

Related guides

Still stuck? Open a support ticket and the Instant Access Internet Services team will help.

Ultrafast LiteSpeed hosting from InstantAccess.net: free SSL, free backups, cPanel included, no contracts. Check out our $10/month hosting.
  • enable dnssec cpanel, dnssec ds record registrar, cpanel dnssec create key, dnssec broke my domain, how to disable dnssec, dnssec servfail, dnssec key tag digest
  • 0 Kunder som kunne bruge dette svar
Hjalp dette svar dig?

Relaterede artikler

How to Use Microsoft 365 or Google Workspace Email with Your Domain

You can keep your website with us and use Microsoft 365 (Outlook) or Google Workspace (Gmail) for...

Our Nameservers: How to Point Your Domain to Your Hosting

To make your website and email work on your hosting account, your domain has to point to the...

DNS Propagation: Why Domain Changes Take Time and How to Check

When you change your nameservers or edit a DNS record, some people see the change right away...

How to Set Up Dynamic DNS in cPanel

Dynamic DNS (DDNS) lets you reach a device on a home or office connection, such as a camera, NAS...

Free SSL Certificates: How AutoSSL and SSL/TLS Status Work

Every hosting account includes free SSL certificates, so your website loads over HTTPS with a...