{"id":965,"date":"2025-12-19T13:22:56","date_gmt":"2025-12-19T12:22:56","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=965"},"modified":"2026-06-07T19:34:15","modified_gmt":"2026-06-07T17:34:15","slug":"what-is-dnssec","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-dnssec\/","title":{"rendered":"What is DNSSEC"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\"><strong>DNSSEC<\/strong> (Domain Name System Security Extensions) is a security mechanism that enhances DNS authentication by using digital signatures based on public-key cryptography.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Its primary purpose is to protect users from attacks that attempt to redirect them to fraudulent websites by ensuring that DNS responses originate from the legitimate source and have not been modified during transmission.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-dnssec\/#How_Does_DNSSEC_Work\" >How Does DNSSEC Work?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-dnssec\/#Verification_Process\" >Verification Process<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-dnssec\/#Example\" >Example<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-dnssec\/#Benefits_of_DNSSEC\" >Benefits of DNSSEC<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-dnssec\/#Protection_Against_DNS_Spoofing\" >Protection Against DNS Spoofing<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-dnssec\/#Protection_Against_Cache_Poisoning\" >Protection Against Cache Poisoning<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-dnssec\/#Improved_Trust\" >Improved Trust<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-dnssec\/#Stronger_Domain_Security\" >Stronger Domain Security<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-dnssec\/#What_DNSSEC_Does_Not_Do\" >What DNSSEC Does Not Do<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-dnssec\/#DNSSEC_Chain_of_Trust\" >DNSSEC Chain of Trust<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-dnssec\/#Why_Enable_DNSSEC\" >Why Enable DNSSEC?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-dnssec\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_Does_DNSSEC_Work\"><\/span>How Does DNSSEC Work?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<\/div>\n\n<div id=\"mybox-2083304555\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">Unlike traditional DNS, DNSSEC does not encrypt DNS queries or responses. Instead, it cryptographically signs the DNS records themselves.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Each DNS zone contains:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A private key<\/li>\n\n\n\n<li>A public key<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The domain or DNS zone owner uses the private key to generate digital signatures for DNS records within the zone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The public key is published in the DNS zone and is available to anyone who needs to verify the authenticity of the signed records.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Verification_Process\"><\/span>Verification Process<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When a DNS resolver receives DNS data from a DNSSEC-enabled zone:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>The resolver retrieves the DNS record.<\/li>\n\n\n\n<li>The resolver retrieves the zone&#8217;s public key.<\/li>\n\n\n\n<li>The digital signature is verified using the public key.<\/li>\n\n\n\n<li>If the signature is valid, the DNS data is considered authentic and is returned to the user.<\/li>\n\n\n\n<li>If the signature cannot be verified, the resolver treats the response as potentially malicious and rejects it.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Example\"><\/span>Example<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Without DNSSEC:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>User \u2192 DNS Resolver \u2192 DNS Server\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The resolver must trust that the received response is legitimate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With DNSSEC:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>User \u2192 DNS Resolver \u2192 DNS Server\n                     \u2193\n             Digital Signature\n                     \u2193\n             Signature Validation\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The resolver verifies that the DNS records have not been altered and genuinely originate from the authoritative DNS server.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Benefits_of_DNSSEC\"><\/span>Benefits of DNSSEC<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Protection_Against_DNS_Spoofing\"><\/span>Protection Against DNS Spoofing<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">DNSSEC helps prevent attackers from injecting fake DNS responses into the DNS resolution process.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Protection_Against_Cache_Poisoning\"><\/span>Protection Against Cache Poisoning<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Attackers cannot easily poison DNS caches with forged records because invalid signatures will fail verification.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Improved_Trust\"><\/span>Improved Trust<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Users and applications can be more confident that they are connecting to the intended website or service.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Stronger_Domain_Security\"><\/span>Stronger Domain Security<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">DNSSEC adds an additional layer of security on top of standard DNS infrastructure.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_DNSSEC_Does_Not_Do\"><\/span>What DNSSEC Does Not Do<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">DNSSEC is often misunderstood as a privacy or encryption technology.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">DNSSEC does <strong>not<\/strong>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Encrypt DNS traffic<\/li>\n\n\n\n<li>Hide DNS queries<\/li>\n\n\n\n<li>Protect website content<\/li>\n\n\n\n<li>Replace SSL\/TLS certificates<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For encrypted DNS traffic, technologies such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>DNS over HTTPS (DoH)<\/li>\n\n\n\n<li>DNS over TLS (DoT)<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">must be used.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"DNSSEC_Chain_of_Trust\"><\/span>DNSSEC Chain of Trust<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">DNSSEC relies on a chain of trust that starts at the DNS root zone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Each level validates the level below it:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Root Zone\n    \u2193\nTop-Level Domain (.com, .net, .ro, etc.)\n    \u2193\nDomain Name\n    \u2193\nDNS Records\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This chain allows resolvers to verify that DNS information remains authentic throughout the entire lookup process.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_Enable_DNSSEC\"><\/span>Why Enable DNSSEC?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Enabling DNSSEC can:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Increase domain security.<\/li>\n\n\n\n<li>Reduce the risk of DNS-based attacks.<\/li>\n\n\n\n<li>Improve trust in your website and online services.<\/li>\n\n\n\n<li>Protect visitors from being redirected to malicious destinations.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">DNSSEC is particularly recommended for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Business websites<\/li>\n\n\n\n<li>E-commerce stores<\/li>\n\n\n\n<li>Banking and financial services<\/li>\n\n\n\n<li>Government websites<\/li>\n\n\n\n<li>Email services<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">DNSSEC (Domain Name System Security Extensions) protects DNS data by using digital signatures and public-key cryptography.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When DNSSEC is enabled:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>DNS records are digitally signed by the zone owner.<\/li>\n\n\n\n<li>DNS resolvers verify those signatures using the published public key.<\/li>\n\n\n\n<li>Authentic records are returned to users.<\/li>\n\n\n\n<li>Invalid or tampered records are rejected.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">This helps protect against DNS spoofing, cache poisoning, and other attacks that attempt to manipulate DNS responses.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[128],"manual_kb_tag":[951,952,953,954,955,956,203,957,942,958,943,959,944,960,945,961,946,947,948,949,950],"class_list":["post-965","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-domains","manual_kb_tag-dns-data-integrity","manual_kb_tag-public-key","manual_kb_tag-private-key","manual_kb_tag-key-pair","manual_kb_tag-key-management","manual_kb_tag-recursive-resolver","manual_kb_tag-dns-zone","manual_kb_tag-zone-owner","manual_kb_tag-dnssec","manual_kb_tag-chain-of-trust","manual_kb_tag-digital-signatures","manual_kb_tag-authoritative-dns-server","manual_kb_tag-public-key-cryptography","manual_kb_tag-cryptographic-signing","manual_kb_tag-dns-security","manual_kb_tag-signed-zone","manual_kb_tag-zone-signing","manual_kb_tag-signed-dns-records","manual_kb_tag-signature-verification","manual_kb_tag-signature-validation","manual_kb_tag-data-authenticity"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/965","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/965\/revisions"}],"predecessor-version":[{"id":9890,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/965\/revisions\/9890"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=965"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=965"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=965"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}