Applies to: All plans (for domains registered or transferred through Maxinodes whose DNS is hosted and signed by another provider).
Before you start: You need access to your client area at my.maxinodes.com and the domain you want to secure. Your DS record details come from the provider that signs your domain's zone (always a separate DNS provider), so have those values ready first.
DNSSEC (Domain Name System Security Extensions) adds a layer of cryptographic signing to your domain's DNS. It lets resolvers verify that the DNS answers a visitor receives genuinely came from your domain and were not tampered with in transit. You enable it by publishing a DS (Delegation Signer) record at the registry, which you do from your client area.
Important: DNSSEC only works if something is signing your domain's zone. Zones hosted on our own nameservers (ns1.maxinodes.com and ns2.maxinodes.com) are not signed, so there are no DS values to publish and DNSSEC is not available for those domains today. The steps below apply when your domain is registered or transferred through Maxinodes and its DNS is hosted elsewhere, with a provider that signs the zone and gives you DS values.
What DNSSEC is and when to use it
Normal DNS has no built-in way to prove an answer is authentic, which leaves room for cache-poisoning and spoofing attacks. DNSSEC closes that gap by chaining a signature from the registry down to your zone, so resolvers can reject forged responses.
Where your zone is signed by an external provider, consider turning DNSSEC on if:
- You handle logins, payments, or sensitive data and want extra protection against DNS spoofing.
- Your industry, compliance rules, or security policy expect it.
- You use a DNS setup that supplies DS/DNSKEY values for you to publish.
A few things to know first:
- DNSSEC is configured per domain, not per hosting account.
- The DS record can only be lodged for domains registered or transferred through Maxinodes, where we manage the registry side from your client area. That is a requirement, not a guarantee — your zone also has to be signed (see below). For a domain registered elsewhere, you enable DNSSEC at that registrar instead.
- If your domain's DNS is hosted by us, on our own nameservers (ns1.maxinodes.com and ns2.maxinodes.com), we do not sign those zones. They have no DNSKEY and no DS, so there is nothing to publish and DNSSEC is not available for that domain today. The DNSSEC option in your client area is for a domain whose DNS is hosted somewhere else, by a provider that signs the zone and hands you the DS values.
- The DS values must match whatever is signing your zone, so do not enable DNSSEC with mismatched or guessed values — a wrong DS record can make your whole domain fail to resolve.
How to add DS records in your client area
- Log in to your client area at my.maxinodes.com.
- Go to Domains -> My Domains.
- Click the domain you want to secure to open its management page.
- Open the option labelled DNSSEC in the domain's management menu.
- Add a DS record using the values from your DNS/zone-signing provider. A DS record typically asks for: Key Tag, Algorithm, Digest Type, and the Digest (the hash). Enter each field exactly as supplied.
- Save the record.
Result: Your DS record is submitted to the registry. Once the registry publishes it, resolvers can validate your domain's DNS responses. Publication and global propagation can take some time, often up to 24 hours.
To turn DNSSEC off later, return to the same DNSSEC option and remove the DS record.
Troubleshooting this task
- I do not see a DNSSEC option. Confirm the domain is registered or transferred through Maxinodes (check Domains -> My Domains). Domains registered elsewhere are managed at that registrar.
- The site stopped resolving after I enabled it. This usually means the DS values do not match the zone's signing keys. Remove the DS record to disable DNSSEC, confirm the correct values with your DNS provider, then re-add it.
- I do not have DS values. DS/DNSKEY details are generated by whatever signs your zone, so they come from the DNS provider hosting that zone — look for a DNSSEC or zone-signing section in their control panel. If your DNS is on our nameservers (ns1.maxinodes.com and ns2.maxinodes.com), there are no DS values to enter: those zones are not signed. To use DNSSEC on a domain registered with us, host its DNS with a provider that signs the zone, then add the DS values it gives you here.
- Changes are not visible yet. Allow time for the registry to publish and for DNS to propagate before testing again.
Comments
0 comments
Please sign in to leave a comment.