// domain glossary
DNSSEC.
DNSSEC is a set of DNS extensions that cryptographically sign a domain's records so that resolvers can verify the answers they receive are genuine and have not been tampered with in transit.
Plain DNS answers are unauthenticated, which means a resolver has no way to tell a genuine response from a forged one injected along the path — the basis of cache poisoning and a range of redirection attacks. DNSSEC fixes that by signing records and building a chain of trust from the DNS root, down through the TLD, to your zone. A validating resolver checks the signatures and refuses answers that do not verify. Note what it does not do: DNSSEC authenticates DNS answers, it does not encrypt them, and it has nothing to say about the traffic that follows.
The moving parts are worth understanding because one of them is the thing that breaks. Your DNS provider signs the zone and holds the keys. A DS record — a digest of your signing key — is then published at the registry through your registrar, and that DS record is the link joining your zone to the chain above it. Your DNS provider owns the keys; your registrar owns the DS record. When those two disagree, validation fails.
Which brings us to the transfer trap, and it is a genuinely expensive one. If you move registrar or change DNS provider while DNSSEC is enabled, and the DS record at the registry no longer matches the keys actually signing your zone, validating resolvers will not serve a degraded answer — they will refuse to resolve the domain at all. The site vanishes for a large share of the internet, mail stops, and the cached failures persist for as long as the TTLs say. The safe order is: disable DNSSEC, wait for the old records to expire from caches, complete the move, then re-enable it at the destination. Anyone practising renewal arbitrage across a portfolio should check which names are signed before scheduling any transfers.
Is it worth enabling? For a domain carrying mail, payments or authentication, yes — it also underpins DANE and several mail-security arrangements, and it is increasingly expected in security reviews. For a parked domain you rarely touch, it is one more thing that can silently break. It is not a substitute for TLS, and it is not a substitute for a competent DNS provider.
Because it is exposed in RDAP, whether a domain is signed is knowable without asking anyone. Owndle records it as part of enrichment, so your portfolio flags the signed names before you start moving them rather than after.
// stop checking one at a time
knowing the terms is the easy part.
Owndle tracks every domain you own across every registrar — what each one costs to renew, what you would save moving it, and when it expires. Free for your first ten domains.
start free — 10 domains →// no card · magic-link sign-in · alerts at 90/30/7/1 days