phas.au

DNSSEC

One switch for domains registered with phas. For domains registered elsewhere, the DS record is shown ready to paste.

DNSSEC signs your zone so resolvers can tell a genuine answer from a forged one. It closes off a class of attack where a visitor is quietly sent to a different server than your records say.

Domains registered with phas

Open the zone under DNS and switch DNSSEC on in the Security card. The zone is signed and the DS record is published at the registry for you. There is nothing to copy anywhere. Switching it off withdraws the DS record first and then unsigns the zone, so the domain never goes dark in between.

Domains registered elsewhere

The switch signs the zone and shows the DS record. Paste it into your registrar's DNSSEC settings; until then the signature is unused, which is harmless. Remove the DS record at the registrar before switching DNSSEC off here, or resolvers will reject the domain's answers.

Before moving DNS

If the domain will move to another DNS provider, switch DNSSEC off first and wait for the change to settle. A signed zone whose keys move providers breaks resolution for as long as the old DS record remains.


Didn't find what you needed? Get in touch.