Applies to: All plans (for domains registered or transferred through Maxinodes).
Before you start: You need access to your client area at my.maxinodes.com and the domain you want to secure. If a third party generates your DS record details (for example a separate DNS provider), have those values ready first.
DNSSEC (Domain Name System Security Extensions) adds a layer of cryptographic signing to your domain's DNS. It lets resolvers verify that the DNS answers a visitor receives genuinely came from your domain and were not tampered with in transit. You enable it by publishing a DS (Delegation Signer) record at the registry, which you do from your client area.
What DNSSEC is and when to use it
Normal DNS has no built-in way to prove an answer is authentic, which leaves room for cache-poisoning and spoofing attacks. DNSSEC closes that gap by chaining a signature from the registry down to your zone, so resolvers can reject forged responses.
Consider turning DNSSEC on if:
- You handle logins, payments, or sensitive data and want extra protection against DNS spoofing.
- Your industry, compliance rules, or security policy expect it.
- You use a DNS setup that supplies DS/DNSKEY values for you to publish.
A few things to know first:
- DNSSEC is configured per domain, not per hosting account.
- It only applies to domains registered or transferred through Maxinodes, where we manage the registry-side DS record from your client area. For a domain registered elsewhere, you enable DNSSEC at that registrar instead.
- Your Maxinodes DNS is managed by us, on our own nameservers (ns1.maxinodes.com and ns2.maxinodes.com). The DS values must match whatever is signing your zone, so do not enable DNSSEC with mismatched or guessed values — a wrong DS record can make your whole domain fail to resolve.
How to add DS records in your client area
- Log in to your client area at my.maxinodes.com.
- Go to Domains -> My Domains.
- Click the domain you want to secure to open its management page.
- Open the option labelled DNSSEC in the domain's management menu.
- Add a DS record using the values from your DNS/zone-signing provider. A DS record typically asks for: Key Tag, Algorithm, Digest Type, and the Digest (the hash). Enter each field exactly as supplied.
- Save the record.
Result: Your DS record is submitted to the registry. Once the registry publishes it, resolvers can validate your domain's DNS responses. Publication and global propagation can take some time, often up to 24 hours.
To turn DNSSEC off later, return to the same DNSSEC option and remove the DS record.
Troubleshooting this task
- I do not see a DNSSEC option. Confirm the domain is registered or transferred through Maxinodes (check Domains -> My Domains). Domains registered elsewhere are managed at that registrar.
- The site stopped resolving after I enabled it. This usually means the DS values do not match the zone's signing keys. Remove the DS record to disable DNSSEC, confirm the correct values with your DNS provider, then re-add it.
- I do not have DS values. DNSSEC needs DS/DNSKEY details generated by whatever signs your zone. If you are unsure where these come from, contact us before changing anything.
- Changes are not visible yet. Allow time for the registry to publish and for DNS to propagate before testing again.
Comments
0 comments
Please sign in to leave a comment.