DNSSEC
Look up the DNSSEC setting of an Edge DNS zone, its status values, the DS record your registrar needs, and what turning DNSSEC off changes.
DNSSEC is a setting of an Edge DNS zone. When it is on, Azion signs the zone’s answers and generates the delegation signer (DS) values that your registrar publishes for the domain. The sections below list the setting, its status values, the DS record, and what changes when DNSSEC is off. For how signatures and validation work, refer to How Edge DNS works. For the procedure, refer to Turn on DNSSEC for a zone.
DNSSEC setting
One field turns DNSSEC on or off for a zone. In the Console, the field is the Enable DNSSEC switch in the DNSSEC section. The section sits on the Create Zone page and on the zone’s Main Settings tab, where Save applies the switch.
| Console | API field | CLI flag | Type | Required | Default | Values |
|---|---|---|---|---|---|---|
| Enable DNSSEC | enabled | --enabled=true or --enabled=false | boolean | Yes, in a PUT | Off in the Console, false in the API | true signs the zone and generates its DS values. false stops the signatures and clears the DS values. |
DNSSEC needs no request to Azion: you turn it on yourself, from the Console, the CLI, or the API. The API takes no key, algorithm, or digest type, because enabled is the only field a request sends. The rest of the object is read-only:
| Operation | API | CLI |
|---|---|---|
| Read DNSSEC | GET /v4/workspace/dns/zones/<zone-id>/dnssec | azion describe dnssec --zone-id <zone-id> |
| Turn DNSSEC on | PATCH /v4/workspace/dns/zones/<zone-id>/dnssec with {"enabled":true} | azion update dnssec --zone-id <zone-id> --enabled=true |
| Turn DNSSEC off | PATCH /v4/workspace/dns/zones/<zone-id>/dnssec with {"enabled":false} | azion update dnssec --zone-id <zone-id> --enabled=false |
The API also accepts PUT on the same path with the same body. Every request carries the header Authorization: Token [TOKEN VALUE]. azion describe dnssec prints Enabled: and Status:, and with --format json it prints the whole object, delegation_signer included. azion update dnssec prints DNSSEC of DNS zone <zone-id> was updated.
Write the CLI flag with an equals sign, --enabled=true or --enabled=false.
Status
The DNSSEC status field of a zone tells whether Azion has signed the zone and generated its DS values. The API returns it in the zone’s DNSSEC object, and azion describe dnssec prints it as Status:. The Console does not show the status; read it with the API or the CLI.
| Status | enabled | delegation_signer | What it means |
|---|---|---|---|
unconfigured | false | null | DNSSEC was never turned on for the zone. |
waiting | true | null | DNSSEC is on, and Azion is signing the zone and generating its DS values. The status moves to ready when Azion finishes. |
ready | true | The four DS values | Azion signed the zone, and the DS values are ready to give to your registrar. |
A request that turns DNSSEC on returns the waiting status, before the DS values exist:
The ready status describes Azion’s side only. A zone reaches ready whether or not its domain is delegated to Azion’s nameservers, and before any registrar holds the DS record. Validating resolvers start to check the zone’s signatures only once the registrar publishes the DS record.
After DNSSEC is turned off, status keeps reading ready, while enabled reads false and delegation_signer reads null. Read enabled to know whether the zone is signed.
DS record
The DS record links a zone’s keys to its parent zone. It carries a hash, the digest, of the zone’s key-signing key, and the registrar publishes it so that validating resolvers can trust the zone’s keys. When the DNSSEC status is ready, the API returns the four DS values in delegation_signer:
In the Console, the same four values appear as locked fields under Enable DNSSEC, each with a copy button. Before the values exist, each field reads Create to show on the Create Zone page and Save to show on Main Settings. After you save with the switch on, reload the page to see the values.
| Console | API field | Example | What it is |
|---|---|---|---|
| Key Tag | key_tag | 12345 | The identifier of the key that signs the zone, an integer from 1 to 65535. |
| Algorithm | algorithm_type | 13, ECDSAP256SHA256 | The algorithm of the zone’s keys. The API returns its number in id and its name in slug; the Console shows the name. |
| Digest Type | digest_type | 2, SHA256 | The hash function that produced the digest, with its number in id and its name in slug. |
| Digest | digest | 3d22…fc79 | The hash of the zone’s key-signing key, a hexadecimal string of 64 characters with SHA256. |
Azion chooses the algorithm and the digest type; no field sets them. At your registrar, add a DS record with the four values, in this order: key tag, algorithm number, digest type number, and digest. For the values above, the record reads:
The domain’s top-level domain (TLD) registry must support DNSSEC for the DS record to be published. After you add the record, the registrar and the TLD registry publish it on their own schedule, which can take up to 48 hours. To check the chain of trust once it is published, use the DNSSEC Analyzer.
Azion generates the zone’s keys and publishes them, and you add no DNSSEC record to the zone. Once the status is ready, Azion’s nameservers publish two DNSKEY records with algorithm 13. Flags 257 mark the key-signing key, and flags 256 mark the zone-signing key. Each answer then carries an RRSIG record, its signature. The DS - Delegation Signer option of Record Type is a different object: a DS record inside your zone, which delegates a child zone. For its format, refer to Record types.
Turning DNSSEC off
Turn DNSSEC off for a signed domain in a fixed order. First, remove the DS record at your registrar. Then wait for the removed DS record to expire from resolver caches. Last, turn DNSSEC off for the zone at Azion.
In the reverse order, the domain can become unavailable to validating resolvers. While the registrar still publishes the DS record, or resolvers still cache it, they expect signed answers that Azion no longer sends.
Turning DNSSEC off for a zone changes these values and answers:
enabledreadsfalse, anddelegation_signerreadsnull.statuskeeps readingready.- Azion’s nameservers stop adding
RRSIGrecords to answers. - Caches can keep serving the zone’s
DNSKEYrecords until their TTL of 3600 seconds expires.
Turning DNSSEC on again for the same zone returns the same four DS values, so a DS record your registrar still holds matches them.
In the Console, turn off the same Enable DNSSEC switch on Main Settings and select Save. For the full procedure in every interface, refer to Turn on DNSSEC for a zone.