DNSSEC signs your zone so resolvers can tell a genuine answer from a forged one. It closes off a class of attack where a visitor is quietly sent to a different server than your records say.
Domains registered with phas
Open the zone under DNS and switch DNSSEC on in the Security card.
The zone is signed and the DS record is published at the registry for you.
There is nothing to copy anywhere. Switching it off withdraws the DS
record first and then unsigns the zone, so the domain never goes dark in
between.
Domains registered elsewhere
The switch signs the zone and shows the DS record. Paste it into your
registrar's DNSSEC settings; until then the signature is unused, which is
harmless. Remove the DS record at the registrar before switching
DNSSEC off here, or resolvers will reject the domain's answers.
Before moving DNS
If the domain will move to another DNS provider, switch DNSSEC off first and
wait for the change to settle. A signed zone whose keys move providers
breaks resolution for as long as the old DS record remains.