# Azion CLI dnssec

The Azion CLI `dnssec` commands describe and update the [DNSSEC](/en/documentation/platform/edge-dns/dnssec/) setting of an [Edge DNS](/en/documentation/platform/edge-dns/) zone: whether DNSSEC is on, its status, and the delegation signer (DS) values of the zone. DNSSEC belongs to a zone, so the CLI has no command that creates, lists, or deletes it. The options every command accepts, such as `--format`, `--out`, and `-y`, are on [Global options](/en/documentation/devtools/cli/globals/).

---

## Describe

`azion describe dnssec` prints the DNSSEC setting of one DNS zone:

```bash
azion describe dnssec [flags]
```

| Flag        | Short | Type | Default | Description                                   |
| ----------- | ----- | ---- | ------- | --------------------------------------------- |
| `--zone-id` | —     | int  | —       | **Required.** ID of the DNS zone to describe. |

This command describes the DNSSEC setting of a zone where DNSSEC has never been turned on:

```bash
azion describe dnssec --zone-id 1234
```

The command prints whether DNSSEC is on and its status:

```text
Enabled:   false
Status:    unconfigured
```

With `--format json`, the command prints the full object: `delegation_signer`, `enabled`, and `status`. The `delegation_signer` object holds the DS values, `algorithm_type`, `digest`, `digest_type`, and `key_tag`, and is `null` while DNSSEC is off. This command prints the object of the same zone after DNSSEC is turned on:

```bash
azion describe dnssec --zone-id 1234 --format json
```

The command prints the DS values of the zone:

```json
{
 "delegation_signer": {
  "algorithm_type": {
   "id": 13,
   "slug": "ECDSAP256SHA256"
  },
  "digest": "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
  "digest_type": {
   "id": 2,
   "slug": "SHA256"
  },
  "key_tag": 12369
 },
 "enabled": true,
 "status": "ready"
}
```

With `--out`, the command writes the same JSON to a file and prints `File successfully written to:` followed by the path. For what each status means and where the DS values go, refer to [DNSSEC](/en/documentation/platform/edge-dns/dnssec/).

A zone ID that matches no zone of your account fails with this error:

```text
Error: Failed to describe the DNSSEC: The given ID or API's endpoint doesn't exist or isn't available. Check that the identifying information is correct. Check your settings and try again. If the error persists, contact Azion support.
```

---

## Update

`azion update dnssec` turns DNSSEC on or off for a DNS zone:

```bash
azion update dnssec [flags]
```

| Flag        | Short | Type   | Default | Description                                                                                                                                                                      |
| ----------- | ----- | ------ | ------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--enabled` | —     | —      | —       | **Required** unless `--file` is set. Turns DNSSEC on (`true`) or off (`false`) for the zone. Without it, the command asks `Enter whether DNSSEC should be enabled (true/false)`. |
| `--file`    | —     | string | —       | Path to a JSON file with the DNSSEC setting. Use `-` to read the JSON from standard input.                                                                                       |
| `--zone-id` | —     | int    | —       | **Required.** ID of the DNS zone to update.                                                                                                                                      |

Write the `--enabled` value with an equals sign, as in `--enabled=false`: `--enabled false`, with a space, prints the success line and leaves DNSSEC on.

This command turns DNSSEC off for the zone with ID `1234`:

```bash
azion update dnssec --zone-id 1234 --enabled=false
```

The command confirms the update:

```text
DNSSEC of DNS zone 1234 was updated
```

After this update, `azion describe dnssec --zone-id 1234 --format json` reads `"enabled": false` and `"status": "ready"`.

---

## Use a JSON file

`azion update dnssec` reads the DNSSEC setting from a JSON file with `--file`. The command reads `enabled` from the file, and `--zone-id` stays on the command line.

This file turns DNSSEC on:

```json
{
  "enabled": true
}
```

Pass the file to the update command:

```bash
azion update dnssec --zone-id 1234 --file dnssec-update.json
```

The command confirms the update:

```text
DNSSEC of DNS zone 1234 was updated
```

After this update, `azion describe dnssec --zone-id 1234 --format json` reads `"enabled": true` and `"status": "ready"`.

---

## Related resources

- [Global options](/en/documentation/devtools/cli/globals.md): The options every command accepts, such as `--format`, `--out`, and `-y`.
- [DNSSEC](/en/documentation/platform/edge-dns/dnssec.md): What each DNSSEC status means and how the DS values reach your registrar.
- [Azion CLI dns-zone](/en/documentation/devtools/cli/resources/dns-zone.md): The commands that create and manage the zones whose IDs these commands take.
- [Azion CLI dns-record](/en/documentation/devtools/cli/resources/dns-record.md): The commands that create and manage the records of a zone.
