What is DNSSEC and why does it matter?

KB-2.5 · 1 min · Updated September 2026

DNSSEC (Domain System Security Extensions) adds a layer of cryptographic verification to DNS, so a resolver can confirm that the DNS answer it received actually came from the domain's real authoritative nameservers and wasn't tampered with in transit.

Without DNSSEC, DNS itself has no built-in way to detect a forged response. An attacker positioned between a user and the real DNS servers could return a false answer, a technique called DNS spoofing or cache poisoning, silently redirecting traffic somewhere it shouldn't go, without either side realizing anything's wrong. DNSSEC closes that gap by having each layer of the DNS hierarchy digitally sign its records, so a forged response fails verification instead of being trusted.

For domains using NameBright's own nameservers, NameBright signs the zone automatically; there are no keys to generate or publish yourself. For domains using an outside nameserver, NameBright supports adding a DS record instead, which is how you publish that outside provider's DNSSEC key information at the registry level. A DS record has four fields: Key Tag, Algorithm, Digest Type, and Digest, all supplied by your nameserver provider.

Related