# DNSSEC

DNSSEC is a setting of an [Edge DNS](/en/documentation/platform/edge-dns/) zone. When it is on, Azion signs the zone's answers and generates the delegation signer (DS) values that your registrar publishes for the domain. The sections below list the setting, its status values, the DS record, and what changes when DNSSEC is off. For how signatures and validation work, refer to [How Edge DNS works](/en/documentation/platform/edge-dns/how-it-works/#dnssec). For the procedure, refer to [Turn on DNSSEC for a zone](/en/documentation/guides/application-security/dns/activate-dnssec/).

---

## DNSSEC setting

One field turns DNSSEC on or off for a zone. In the Console, the field is the **Enable DNSSEC** switch in the **DNSSEC** section. The section sits on the **Create Zone** page and on the zone's **Main Settings** tab, where **Save** applies the switch.

| Console           | API field | CLI flag                              | Type    | Required        | Default                                | Values                                                                                                    |
| ----------------- | --------- | ------------------------------------- | ------- | --------------- | -------------------------------------- | --------------------------------------------------------------------------------------------------------- |
| **Enable DNSSEC** | `enabled` | `--enabled=true` or `--enabled=false` | boolean | Yes, in a `PUT` | Off in the Console, `false` in the API | `true` signs the zone and generates its DS values. `false` stops the signatures and clears the DS values. |

DNSSEC needs no request to Azion: you turn it on yourself, from the Console, the CLI, or the API. The API takes no key, algorithm, or digest type, because `enabled` is the only field a request sends. The rest of the object is read-only:

| Operation       | API                                                                       | CLI                                                       |
| --------------- | ------------------------------------------------------------------------- | --------------------------------------------------------- |
| Read DNSSEC     | `GET /v4/workspace/dns/zones/<zone-id>/dnssec`                            | `azion describe dnssec --zone-id <zone-id>`               |
| Turn DNSSEC on  | `PATCH /v4/workspace/dns/zones/<zone-id>/dnssec` with `{"enabled":true}`  | `azion update dnssec --zone-id <zone-id> --enabled=true`  |
| Turn DNSSEC off | `PATCH /v4/workspace/dns/zones/<zone-id>/dnssec` with `{"enabled":false}` | `azion update dnssec --zone-id <zone-id> --enabled=false` |

The API also accepts `PUT` on the same path with the same body. Every request carries the header `Authorization: Token [TOKEN VALUE]`. `azion describe dnssec` prints `Enabled:` and `Status:`, and with `--format json` it prints the whole object, `delegation_signer` included. `azion update dnssec` prints `DNSSEC of DNS zone <zone-id> was updated`.

Write the CLI flag with an equals sign, `--enabled=true` or `--enabled=false`.

---

## Status

The DNSSEC `status` field of a zone tells whether Azion has signed the zone and generated its DS values. The API returns it in the zone's DNSSEC object, and `azion describe dnssec` prints it as `Status:`. The Console does not show the status; read it with the API or the CLI.

| Status         | `enabled` | `delegation_signer` | What it means                                                                                                              |
| -------------- | --------- | ------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| `unconfigured` | `false`   | `null`              | DNSSEC was never turned on for the zone.                                                                                   |
| `waiting`      | `true`    | `null`              | DNSSEC is on, and Azion is signing the zone and generating its DS values. The status moves to `ready` when Azion finishes. |
| `ready`        | `true`    | The four DS values  | Azion signed the zone, and the DS values are ready to give to your registrar.                                              |

A request that turns DNSSEC on returns the `waiting` status, before the DS values exist:

```json
{
  "state": "executed",
  "data": {
    "enabled": true,
    "status": "waiting",
    "delegation_signer": null
  }
}
```

The `ready` status describes Azion's side only. A zone reaches `ready` whether or not its domain is delegated to Azion's nameservers, and before any registrar holds the DS record. Validating resolvers start to check the zone's signatures only once the registrar publishes the DS record.

After DNSSEC is turned off, `status` keeps reading `ready`, while `enabled` reads `false` and `delegation_signer` reads `null`. Read `enabled` to know whether the zone is signed.

---

## DS record

The DS record links a zone's keys to its parent zone. It carries a hash, the digest, of the zone's key-signing key, and the registrar publishes it so that validating resolvers can trust the zone's keys. When the DNSSEC status is `ready`, the API returns the four DS values in `delegation_signer`:

```json
{
  "data": {
    "enabled": true,
    "status": "ready",
    "delegation_signer": {
      "algorithm_type": {"id": 13, "slug": "ECDSAP256SHA256"},
      "digest": "3d22…fc79",
      "digest_type": {"id": 2, "slug": "SHA256"},
      "key_tag": 12345
    }
  }
}
```

In the Console, the same four values appear as locked fields under **Enable DNSSEC**, each with a copy button. Before the values exist, each field reads `Create to show` on the **Create Zone** page and `Save to show` on **Main Settings**. After you save with the switch on, reload the page to see the values.

| Console         | API field        | Example                 | What it is                                                                                                               |
| --------------- | ---------------- | ----------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| **Key Tag**     | `key_tag`        | `12345`                 | The identifier of the key that signs the zone, an integer from 1 to 65535.                                               |
| **Algorithm**   | `algorithm_type` | `13`, `ECDSAP256SHA256` | The algorithm of the zone's keys. The API returns its number in `id` and its name in `slug`; the Console shows the name. |
| **Digest Type** | `digest_type`    | `2`, `SHA256`           | The hash function that produced the digest, with its number in `id` and its name in `slug`.                              |
| **Digest**      | `digest`         | `3d22…fc79`             | The hash of the zone's key-signing key, a hexadecimal string of 64 characters with `SHA256`.                             |

Azion chooses the algorithm and the digest type; no field sets them. At your registrar, add a DS record with the four values, in this order: key tag, algorithm number, digest type number, and digest. For the values above, the record reads:

```text
12345 13 2 3d22…fc79
```

The domain's top-level domain (TLD) registry must support DNSSEC for the DS record to be published. After you add the record, the registrar and the TLD registry publish it on their own schedule, which can take up to 48 hours. To check the chain of trust once it is published, use the [DNSSEC Analyzer](https://dnssec-analyzer.verisignlabs.com/).

Azion generates the zone's keys and publishes them, and you add no DNSSEC record to the zone. Once the status is `ready`, Azion's nameservers publish two `DNSKEY` records with algorithm 13. Flags `257` mark the key-signing key, and flags `256` mark the zone-signing key. Each answer then carries an `RRSIG` record, its signature. The *DS - Delegation Signer* option of **Record Type** is a different object: a DS record inside your zone, which delegates a child zone. For its format, refer to [Record types](/en/documentation/platform/edge-dns/record-types/#ds).

---

## Turning DNSSEC off

Turn DNSSEC off for a signed domain in a fixed order. First, remove the DS record at your registrar. Then wait for the removed DS record to expire from resolver caches. Last, turn DNSSEC off for the zone at Azion.

In the reverse order, the domain can become unavailable to validating resolvers. While the registrar still publishes the DS record, or resolvers still cache it, they expect signed answers that Azion no longer sends.

Turning DNSSEC off for a zone changes these values and answers:

- `enabled` reads `false`, and `delegation_signer` reads `null`.
- `status` keeps reading `ready`.
- Azion's nameservers stop adding `RRSIG` records to answers.
- Caches can keep serving the zone's `DNSKEY` records until their TTL of 3600 seconds expires.

Turning DNSSEC on again for the same zone returns the same four DS values, so a DS record your registrar still holds matches them.

In the Console, turn off the same **Enable DNSSEC** switch on **Main Settings** and select **Save**. For the full procedure in every interface, refer to [Turn on DNSSEC for a zone](/en/documentation/guides/application-security/dns/activate-dnssec/#turn-dnssec-off).

---

## Related resources

- [How Edge DNS works](/en/documentation/platform/edge-dns/how-it-works.md#dnssec): How signed answers, the zone's keys, and the DS record let a validating resolver trust a zone.
- [Turn on DNSSEC for a zone](/en/documentation/guides/application-security/dns/activate-dnssec.md): The steps to turn DNSSEC on in the Console, the CLI, or the API, and to add the DS record at your registrar.
- [Zones and records](/en/documentation/platform/edge-dns/zones-and-records.md): Every zone and record field, the nameservers, and the API errors.
- [Troubleshoot Edge DNS](/en/documentation/platform/edge-dns/troubleshooting.md#validation-fails-after-turning-on-dnssec): What to check when resolvers fail to validate a zone after DNSSEC is turned on.
