DNSSEC adds a digital signature to your domain's DNS records so that internet resolvers can tell a genuine answer from a forged one. It's a two-part job: you create the signing key in cPanel, then add a matching DS record at your domain registrar. This guide shows you how to turn on DNSSEC for your domain in cPanel, how to add the DS record, how to check it's working -- and how to avoid the one mistake that can take your whole domain offline.
What DNSSEC does (and doesn't do)
Normally, when someone types your domain into a browser, their resolver asks for your records and trusts whatever answer comes back. An attacker who can slip in a fake answer (called DNS spoofing or cache poisoning) could send your visitors or your email somewhere else.
With DNSSEC, our nameservers sign your records, and the registry for your domain extension (such as .com) publishes a fingerprint of your key -- the DS record. Resolvers that check DNSSEC follow that chain of trust from the registry to our nameservers. If a signature doesn't match, they refuse the answer.
- It does: protect visitors whose resolvers validate DNSSEC (Google Public DNS, Cloudflare's 1.1.1.1 and many internet providers do) from forged DNS answers.
- It doesn't: encrypt anything, replace your SSL certificate, stop hacking of your website, or speed anything up.
DNSSEC is optional. It's worth turning on if you're comfortable with the steps below and you don't plan to change nameservers soon.
Before you start
- Your domain must use our nameservers: ns5.instantaccess.net, ns6.instantaccess.net, ns1.fanaticalhosting.com and ns2.fanaticalhosting.com. If your DNS is hosted elsewhere (for example Cloudflare or your registrar's DNS), set up DNSSEC with that provider instead. The cPanel key does nothing there.
- Your registrar must support DS records for your domain extension. Most registrars do for .com, .net, .org and most country codes. Look for a "DNSSEC" or "DS records" section in their domain settings.
- Don't plan a nameserver change. If you might move to Cloudflare or another host soon, wait until after the move.
The golden rule: nameservers and DS record must match
Once a DS record is published at the registry, resolvers expect signed answers that match it. If they get answers signed with a different key -- or unsigned answers -- they treat your domain as broken and return an error. Visitors see "This site can't be reached" and email to your domain starts bouncing, even though nothing is wrong with your hosting.
That happens when:
- You change nameservers (to Cloudflare, another host, or your registrar's DNS) while the old DS record is still at the registrar.
- You delete or deactivate the key in cPanel while the DS record is still at the registrar.
- You enter the DS values wrongly at the registrar.
So always remember the order: add the key in cPanel first, then the DS record. When removing DNSSEC: remove the DS record first, wait, then remove the key.
Step 1: Create the DNSSEC key in cPanel
- Log in to cPanel (from the client area, Services > My Services, choose your plan, then Log in to cPanel).
- Go to Domains > Zone Editor.
- Find your domain in the list and click DNSSEC.
- Click Create Key. cPanel shows the settings it will use. You can click Customize to change the algorithm or key setup, but the defaults are the right choice for almost everyone.
- Confirm by clicking Create. After a moment you'll see a new key listed with its Key Tag, algorithm and status. Make sure it shows as Active.
Which algorithm?
| Algorithm | Number | Notes |
|---|---|---|
| ECDSA Curve P-256 with SHA-256 | 13 | Modern, compact and widely supported. A good choice if your registrar lists it. |
| RSA/SHA-256 | 8 | The most widely supported option. Choose this if your registrar's DS form doesn't offer algorithm 13. |
Before you create the key, glance at your registrar's DNSSEC form to see which algorithm numbers it accepts. If it only lists 8, customize the key to RSA/SHA-256.
Step 2: Copy the DS record details
- On the DNSSEC page for your domain, click View DS Records (or open the key's details).
- You'll see the values your registrar needs. Leave this page open.
| Field | What it looks like |
|---|---|
| Key Tag | A number, such as 24617 |
| Algorithm | A number, such as 13 or 8 |
| Digest Type | A number: 2 means SHA-256. If several digests are shown, SHA-256 (type 2) is the one to use. |
| Digest | A long string of letters and numbers (64 characters for SHA-256) |
Some registrars (and some country-code registries) ask for the public key itself instead of a digest. In that case, copy the public key from the key's details in cPanel.
Step 3: Add the DS record at your registrar
- Log in to the company where your domain is registered and open the domain's settings.
- Find the DNSSEC or DS Records section and choose to add a record.
- Enter the Key Tag, Algorithm, Digest Type and Digest exactly as cPanel shows them. Paste the digest rather than typing it, with no spaces.
- Save.
If your domain is registered with us, log in to the client area, go to Domains > My Domains, and open the domain's management page. If you don't see a DNSSEC option there, open a ticket with the four DS values and we'll add them for you.
Step 4: Check it's working
The registry usually publishes the DS record within an hour or so, though it can take longer. Then:
- Go to dnsviz.net, enter your domain and run the analysis. A healthy result shows a chain from the root, through your extension (such as .com), down to your domain, with no red errors.
- Or, on a Mac or Linux computer, run:
The first command should return your Key Tag, algorithm, digest type and digest. In the second, look fordig example.com DS +short dig example.com A +dnssecadin theflags:line when using a validating resolver such as@1.1.1.1, and forRRSIGrecords in the answer. - Load your website and send yourself a test email to confirm everything still works.
Online checkers and the commands for Windows are covered in DNS Propagation: Why Domain Changes Take Time and How to Check.
How to turn DNSSEC off safely
Do this before changing nameservers, moving to Cloudflare, or moving your hosting.
- Remove the DS record at your registrar and save.
- Wait at least 48 hours. Resolvers may still have the old DS record cached. The waiting time depends on the registry, and a day or two covers most of them.
- Check that
dig example.com DS +short(or DNSViz) no longer shows a DS record. - Only then deactivate or delete the key in cPanel (Domains > Zone Editor > DNSSEC), or change your nameservers.
Troubleshooting
My site shows "This site can't be reached" on some networks but not others
This is the classic DNSSEC failure. Validating resolvers (Google, Cloudflare and many ISPs) reject your domain while non-validating ones still work. Check DNSViz. If it shows a DS record that doesn't match any key, either correct the DS record at the registrar or remove it. Open a ticket if you're not sure which to do -- this is urgent, because email to your domain can bounce too.
dig shows SERVFAIL
Run the same lookup with +cd added (for example dig @8.8.8.8 example.com A +cd), which turns validation off. If that works but the normal lookup fails, the problem is DNSSEC, not your records.
The registrar rejects the DS record
Check the algorithm number is one they support, the digest type is 2, and the digest was pasted without spaces. If the registrar only supports algorithm 8 and your key is 13, delete the key in cPanel (it's safe while no DS record is published), create a new one with RSA/SHA-256, and try again.
I deleted the key by mistake and the DS record is still there
Remove the DS record at the registrar right away, then open a ticket. Your domain will recover once resolvers stop caching the old DS record.
Common questions
Do I need DNSSEC?
It's not required for your website, email or SSL certificate to work. It's an extra layer against a specific kind of attack. Some organizations require it for compliance.
Does DNSSEC affect AutoSSL or email?
When set up correctly, no. When set up wrongly, it can break both, because they depend on DNS answers.
Do I need to renew or rotate the key?
Not on a schedule. The key doesn't expire the way an SSL certificate does. If you ever replace it, add the new DS record at the registrar, wait for it to publish, and only then remove the old key and old DS record.
I use Cloudflare. Should I use cPanel's DNSSEC?
No. When Cloudflare hosts your DNS, turn on DNSSEC in the Cloudflare dashboard and use the DS record it gives you.
Can I still edit records in the Zone Editor?
Yes. Edit records as usual. The server re-signs the zone for you.
Related guides
- How to Use the cPanel Zone Editor (A, CNAME, MX and TXT Records)
- Our Nameservers: How to Point Your Domain to Your Hosting
- DNS Propagation: Why Domain Changes Take Time and How to Check
- DNS_PROBE_FINISHED_NXDOMAIN: How to Fix "This Site Can't Be Reached"
Still stuck? Open a support ticket and the Instant Access Internet Services team will help.
