---
name: azion-turn-on-dnssec-for-a-zone
description: >-
  Turn on DNSSEC for an Edge DNS zone in Azion Console, the CLI, or the API, add the DS record at your registrar, check the signatures, and turn it off safely.
---

# Turn on DNSSEC for a zone

You can turn on DNSSEC for a zone in [Edge DNS](/en/documentation/platform/edge-dns/) from Azion Console, the Azion CLI, or the Azion API. Azion then signs the zone's answers, and the DS record you add at your registrar lets validating resolvers check those signatures. To turn DNSSEC on while you create a zone, refer to [Create, edit, or delete a zone](/en/documentation/guides/application-security/dns/edge-dns-configure-main-settings/). For the status values and every DS field, refer to [DNSSEC](/en/documentation/platform/edge-dns/dnssec/).

---

Select your interface once. The prerequisites and every task below show only that path.

## Prerequisites

- A zone in Edge DNS for your domain. To create one, refer to [Create, edit, or delete a zone](/en/documentation/guides/application-security/dns/edge-dns-configure-main-settings/).
- The **Edit Edge DNS** permission. It grants access to create, edit, and remove zones, and it requires **View Edge DNS**. Refer to [Teams permissions](/en/documentation/fundamentals/teams-permissions/).
- Access to your domain's registrar, and a top-level domain (TLD) whose registry supports DNSSEC.
- `dig` on your machine, to check the signatures. To install it, refer to [Query a zone with dig](/en/documentation/guides/application-security/dns/run-the-dig-command/).

**Console**

- Access to Azion Console. To sign in, refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**CLI**

- The [Azion CLI](/en/documentation/devtools/cli/) installed and authorized.
- The ID of your zone. To find it, run `azion list dns-zone`, which prints each zone's `ID`, `NAME`, `DOMAIN`, and `ACTIVE` state.

**API**

- A [personal token](/en/documentation/guides/platform/account-and-billing/personal-tokens/) and `curl`.
- The `id` of your zone. To find it, send a `GET` request to `https://api.azion.com/v4/workspace/dns/zones`, which lists your zones with their `id`.
- For every endpoint and field of the API, refer to the [Azion API reference](https://api.azion.com/).

---

## Turn on DNSSEC

When you turn DNSSEC on, Azion generates the zone's keys, signs its answers, and produces the four values of its DS record. The zone's status reads `waiting` while Azion does this, then `ready`.

**Console**

To turn on DNSSEC in Azion Console:

1. **Open the Edge DNS page**

   Access [Azion Console](https://console.azion.com/) > **Edge DNS**.

2. **Open the zone**

   On the **Zones** page, select the row of the zone. It opens on the **Main Settings** tab.

3. **Turn on Enable DNSSEC**

   In the **DNSSEC** section, turn on **Enable DNSSEC**.

4. **Select Save**

5. **Reload the page**

   The DNSSEC fields keep reading `Save to show` until you reload.

The Console shows `Edge DNS has been updated`. After the reload, the **Key Tag**, **Algorithm**, **Digest Type**, and **Digest** fields show the values your registrar needs, each with a copy button. The Console does not show the DNSSEC status; to read it, use the CLI or the API.

**CLI**

To turn on DNSSEC with the Azion CLI, replace `<zone-id>` with the ID of your zone:

```bash
azion update dnssec --zone-id <zone-id> --enabled=true
```

The command confirms the update:

```text
DNSSEC of DNS zone 1234 was updated
```

To read the status, describe the zone's DNSSEC:

```bash
azion describe dnssec --zone-id <zone-id>
```

The output shows DNSSEC on and its status:

```text
Enabled:   true
Status:    ready
```

If `Status:` reads `waiting`, run the command again after a few seconds. Once it reads `ready`, print the DS values in JSON:

```bash
azion describe dnssec --zone-id <zone-id> --format json
```

The `delegation_signer` object holds the four values your registrar needs:

```json
{
 "delegation_signer": {
  "algorithm_type": {
   "id": 13,
   "slug": "ECDSAP256SHA256"
  },
  "digest": "3d22…fc79",
  "digest_type": {
   "id": 2,
   "slug": "SHA256"
  },
  "key_tag": 12345
 },
 "enabled": true,
 "status": "ready"
}
```

The zone is signed, and its DS values are ready for your registrar.

**API**

To turn on DNSSEC with the Azion API, send a `PATCH` request to the zone's DNSSEC endpoint. Replace `<zone-id>` with the `id` of your zone and `[TOKEN VALUE]` with your personal token:

```bash
curl -X PATCH https://api.azion.com/v4/workspace/dns/zones/<zone-id>/dnssec \
  -H "Authorization: Token [TOKEN VALUE]" \
  -H "Content-Type: application/json" \
  -d '{"enabled":true}'
```

A `200` returns the `waiting` status, before the DS values exist:

```json
{
  "state": "executed",
  "data": {
    "enabled": true,
    "status": "waiting",
    "delegation_signer": null
  }
}
```

To read the DS values, send a `GET` request to the same endpoint:

```bash
curl https://api.azion.com/v4/workspace/dns/zones/<zone-id>/dnssec \
  -H "Authorization: Token [TOKEN VALUE]"
```

Once the status is `ready`, the `delegation_signer` object holds the four values your registrar needs:

```json
{
  "data": {
    "enabled": true,
    "status": "ready",
    "delegation_signer": {
      "algorithm_type": {"id": 13, "slug": "ECDSAP256SHA256"},
      "digest": "3d22…fc79",
      "digest_type": {"id": 2, "slug": "SHA256"},
      "key_tag": 12345
    }
  }
}
```

If `status` still reads `waiting`, send the `GET` request again after a few seconds.

A zone reaches `ready` on Azion's side alone: before any registrar holds its DS record, and even when the domain is not delegated to Azion. For every status value, refer to [DNSSEC](/en/documentation/platform/edge-dns/dnssec/#status).

---

## Add the DS record at your registrar

DNSSEC is not complete until your registrar publishes the zone's DS record. Validating resolvers check the zone's signatures only from then on. The domain must already be delegated to Azion's three nameservers. Otherwise, resolvers find a DS record that the current provider's answers do not match. To delegate the domain, refer to [Migrate nameservers to Azion](/en/documentation/guides/platform/migration/migrate-ns-to-azion/).

If the domain has a DS record from another DNS provider, remove it at your registrar first. Wait for it to expire from resolver caches before you delegate the domain to Azion.

To add the DS record:

1. Copy the four values of the zone's DS record. In the Console, they are the **Key Tag**, **Algorithm**, **Digest Type**, and **Digest** fields on **Main Settings**. In the CLI and the API, they are `key_tag`, `algorithm_type`, `digest_type`, and `digest` in `delegation_signer`.
2. At your registrar, open the DNSSEC settings of the domain.
3. Add a DS record with the key tag, the algorithm, the digest type, and the digest. Azion uses algorithm `13` (`ECDSAP256SHA256`) and digest type `2` (`SHA256`).
4. Save the record at your registrar.

The registrar and the TLD registry publish the DS record on their own schedule, which can take up to 48 hours. For what each value is, refer to [DNSSEC](/en/documentation/platform/edge-dns/dnssec/#ds-record).

---

## Check the signatures

You can check that Azion signs the zone as soon as the status is `ready`, before the DS record is published. To ask Azion's nameserver for the zone's keys, run:

```bash
dig +short @ns1.aziondns.net example.com DNSKEY
```

The answer lists two keys with algorithm `13`. Flags `257` mark the key-signing key, and flags `256` mark the zone-signing key:

```text
257 3 13 fvkK…ikw==
256 3 13 PfUf…4Q==
```

To check that answers carry a signature, query a record of the zone with `+dnssec`:

```bash
dig +dnssec @ns1.aziondns.net www.example.com A
```

The answer section holds the `A` record followed by its `RRSIG` record, with algorithm `13`. For a few minutes after you turn DNSSEC on, an answer cached before the change can come back without an `RRSIG`. Query again until every answer carries one.

An `RRSIG` shows that Azion signs the zone, not that resolvers validate it. Validation starts only after the registrar publishes the DS record. To check the chain of trust then, use either check:

- Query a resolver that validates DNSSEC with `+dnssec`. When the chain of trust holds, the `flags:` line of the answer includes `ad`.
- Enter your domain in the [DNSSEC Analyzer](https://dnssec-analyzer.verisignlabs.com/). Every check must pass.

If validation fails, refer to [Troubleshoot Edge DNS](/en/documentation/platform/edge-dns/troubleshooting/#validation-fails-after-turning-on-dnssec).

---

## Turn DNSSEC off

Turn DNSSEC off for a signed domain in this order:

1. At your registrar, remove the domain's DS record.
2. Wait until resolvers no longer cache the old DS record.
3. Turn DNSSEC off for the zone at Azion, with the procedure below.

> **Caution**
>
> Never turn DNSSEC off at Azion while the registrar still publishes the DS record, or while resolvers still cache it. Validating resolvers then expect signed answers that Azion no longer sends, and the domain can stop resolving for them.

**Console**

To turn off DNSSEC in Azion Console:

1. **Open the Edge DNS page**

   Access [Azion Console](https://console.azion.com/) > **Edge DNS**.

2. **Open the zone**

   On the **Zones** page, select the row of the zone. It opens on the **Main Settings** tab.

3. **Turn off Enable DNSSEC**

   In the **DNSSEC** section, turn off **Enable DNSSEC**.

4. **Select Save**

The Console shows `Edge DNS has been updated`, and the four DS fields no longer appear in the **DNSSEC** section.

**CLI**

To turn off DNSSEC with the Azion CLI, replace `<zone-id>` with the ID of your zone:

```bash
azion update dnssec --zone-id <zone-id> --enabled=false
```

The command confirms the update:

```text
DNSSEC of DNS zone 1234 was updated
```

To check the result, run `azion describe dnssec --zone-id <zone-id>`:

```text
Enabled:   false
Status:    ready
```

`Status:` stays `ready` after DNSSEC is off, so check `Enabled:` to tell whether Azion signs the zone.

**API**

To turn off DNSSEC with the Azion API, send `{"enabled":false}` to the zone's DNSSEC endpoint:

```bash
curl -X PATCH https://api.azion.com/v4/workspace/dns/zones/<zone-id>/dnssec \
  -H "Authorization: Token [TOKEN VALUE]" \
  -H "Content-Type: application/json" \
  -d '{"enabled":false}'
```

To check the result, send a `GET` request to the same endpoint:

```bash
curl https://api.azion.com/v4/workspace/dns/zones/<zone-id>/dnssec \
  -H "Authorization: Token [TOKEN VALUE]"
```

The DNSSEC object reads `enabled` `false` and `delegation_signer` `null`, while `status` keeps reading `ready`:

```json
{
  "data": {
    "enabled": false,
    "status": "ready",
    "delegation_signer": null
  }
}
```

The `enabled` field, not `status`, tells you whether Azion signs the zone.

Azion's nameservers stop adding `RRSIG` records to answers, and caches can keep serving the zone's `DNSKEY` records until their TTL expires.

---

## Next steps

- [DNSSEC](/en/documentation/platform/edge-dns/dnssec.md): Look up the status values and each field of the DS record.
- [How Edge DNS works](/en/documentation/platform/edge-dns/how-it-works.md#dnssec): See how signatures and the DS record let resolvers trust a zone.
- [Migrate nameservers to Azion](/en/documentation/guides/platform/migration/migrate-ns-to-azion.md): Delegate your domain to Edge DNS at the registrar.
- [Troubleshoot Edge DNS](/en/documentation/platform/edge-dns/troubleshooting.md#validation-fails-after-turning-on-dnssec): Fix a zone that resolvers fail to validate.
