DNSSEC explained without the folklore

DNSSEC signs authoritative answers so validating resolvers can reject spoofed records. How it coexists with GeoDNS, Anycast and low TTLs on Cloud DNS.

Unsigned zones can be spoofed between authority and resolver. Teams delay DNSSEC because they think it forbids geo, failover or low TTLs. On Cloud DNS those features still sit on a signed zone.

What validating resolvers gain

DNSSEC lets a supporting resolver check that the answer came from the zone owner. Not every resolver validates. Signing still authenticates the zone for those that do.

DS at the parent

Enabling DNSSEC on Cloud DNS is not finished until DS records are published at the parent. Test with a validating resolver before you treat production as signed.

Low TTLs and signatures

Plan record and signature lifetimes so a one-second TTL and DNSSEC remain compatible. Signing is not an excuse for 24-hour application TTLs.

Vanity nameservers

Branded NS records are supported. Include glue and DS in the plan so the branded names remain valid.

Frequently Asked Questions

No. Validation is done by supporting resolvers. Signing still authenticates the zone for those that do.

DNSSEC signs the zone. Plan the whole zone, including flattening and HTTPS records you use.

Not required. It is available when you want signed answers for the zone.

Run this on Cloud DNS.

Get started with our Management Console in less than 2 minutes, or connect with an expert to supercharge your business today.