Join the waitlist
DNBlackBook Join the waitlist

GlossaryDNS and technical

DNSSEC

DNSSEC (Domain Name System Security Extensions) is a set of extensions that add cryptographic signatures to DNS records, so resolvers can verify that an answer came from the domain's authoritative source and was not altered.

Published by DNBlackBook · Last updated

Join the waitlist

Free to join the waitlist, no payment

Also called Domain Name System Security Extensions · DNS Security Extensions

DNSSEC, explained

The domain's DNS host signs its records, and a DS (delegation signer) record, submitted to the registry through the registrar, links the parent zone, such as .com, to the domain's keys. Validating resolvers follow that chain of signatures; if it breaks, they refuse to answer and the domain stops resolving for their users. DNSSEC authenticates DNS data and protects against forged answers; it does not encrypt anything.

For a domain investor, DNSSEC matters mostly during moves. If a name has DNSSEC enabled and you change its nameservers, for example to a parking or lander service or to a buyer's DNS host, while the old DS record is still at the registry, the name can stop resolving. Turn DNSSEC off at the registrar and let the change take effect before switching nameservers or handing a domain over, then let the new DNS host enable it again.

Example. A sold domain that resolves for some visitors but fails for others right after a nameserver change often still has an old DS record at the registry.

The glossary

204 domain investing terms, defined in plain English.

All terms

Join the waitlist.

The list hears first: when the original 2016 course goes free on YouTube, and when DNBlackBook 2.0 opens in June 2027.

Join the waitlist

Signal, not noise. An email the day the course opens.

The list hears first.

When the original 2016 course goes free on YouTube, and when DNBlackBook 2.0 — Domaining in the Era of AI — opens in June 2027.

No newsletter. No list rentals. Unsubscribe in one click.

Free · No payment