Turn on DNSSEC for a zone
Turn on DNSSEC for an Edge DNS zone in Azion Console, the CLI, or the API, add the DS record at your registrar, check the signatures, and turn it off safely.
You can turn on DNSSEC for a zone in Edge DNS from Azion Console, the Azion CLI, or the Azion API. Azion then signs the zone’s answers, and the DS record you add at your registrar lets validating resolvers check those signatures. To turn DNSSEC on while you create a zone, refer to Create, edit, or delete a zone. For the status values and every DS field, refer to DNSSEC.
Select your interface once. The prerequisites and every task below show only that path.
Prerequisites
- A zone in Edge DNS for your domain. To create one, refer to Create, edit, or delete a zone.
- The Edit Edge DNS permission. It grants access to create, edit, and remove zones, and it requires View Edge DNS. Refer to Teams permissions.
- Access to your domain’s registrar, and a top-level domain (TLD) whose registry supports DNSSEC.
digon your machine, to check the signatures. To install it, refer to Query a zone with dig.
- Access to Azion Console. To sign in, refer to Access Azion Console.
Turn on DNSSEC
When you turn DNSSEC on, Azion generates the zone’s keys, signs its answers, and produces the four values of its DS record. The zone’s status reads waiting while Azion does this, then ready.
To turn on DNSSEC with the Azion CLI, replace <zone-id> with the ID of your zone:
The command confirms the update:
To read the status, describe the zone’s DNSSEC:
The output shows DNSSEC on and its status:
If Status: reads waiting, run the command again after a few seconds. Once it reads ready, print the DS values in JSON:
The delegation_signer object holds the four values your registrar needs:
The zone is signed, and its DS values are ready for your registrar.
A zone reaches ready on Azion’s side alone: before any registrar holds its DS record, and even when the domain is not delegated to Azion. For every status value, refer to DNSSEC.
Add the DS record at your registrar
DNSSEC is not complete until your registrar publishes the zone’s DS record. Validating resolvers check the zone’s signatures only from then on. The domain must already be delegated to Azion’s three nameservers. Otherwise, resolvers find a DS record that the current provider’s answers do not match. To delegate the domain, refer to Migrate nameservers to Azion.
If the domain has a DS record from another DNS provider, remove it at your registrar first. Wait for it to expire from resolver caches before you delegate the domain to Azion.
To add the DS record:
- Copy the four values of the zone’s DS record. In the Console, they are the Key Tag, Algorithm, Digest Type, and Digest fields on Main Settings. In the CLI and the API, they are
key_tag,algorithm_type,digest_type, anddigestindelegation_signer. - At your registrar, open the DNSSEC settings of the domain.
- Add a DS record with the key tag, the algorithm, the digest type, and the digest. Azion uses algorithm
13(ECDSAP256SHA256) and digest type2(SHA256). - Save the record at your registrar.
The registrar and the TLD registry publish the DS record on their own schedule, which can take up to 48 hours. For what each value is, refer to DNSSEC.
Check the signatures
You can check that Azion signs the zone as soon as the status is ready, before the DS record is published. To ask Azion’s nameserver for the zone’s keys, run:
The answer lists two keys with algorithm 13. Flags 257 mark the key-signing key, and flags 256 mark the zone-signing key:
To check that answers carry a signature, query a record of the zone with +dnssec:
The answer section holds the A record followed by its RRSIG record, with algorithm 13. For a few minutes after you turn DNSSEC on, an answer cached before the change can come back without an RRSIG. Query again until every answer carries one.
An RRSIG shows that Azion signs the zone, not that resolvers validate it. Validation starts only after the registrar publishes the DS record. To check the chain of trust then, use either check:
- Query a resolver that validates DNSSEC with
+dnssec. When the chain of trust holds, theflags:line of the answer includesad. - Enter your domain in the DNSSEC Analyzer. Every check must pass.
If validation fails, refer to Troubleshoot Edge DNS.
Turn DNSSEC off
Turn DNSSEC off for a signed domain in this order:
- At your registrar, remove the domain’s DS record.
- Wait until resolvers no longer cache the old DS record.
- Turn DNSSEC off for the zone at Azion, with the procedure below.
To turn off DNSSEC with the Azion CLI, replace <zone-id> with the ID of your zone:
The command confirms the update:
To check the result, run azion describe dnssec --zone-id <zone-id>:
Status: stays ready after DNSSEC is off, so check Enabled: to tell whether Azion signs the zone.
Azion’s nameservers stop adding RRSIG records to answers, and caches can keep serving the zone’s DNSKEY records until their TTL expires.