What DNS does, and why it is a target
When somebody types your domain into a browser, before any page appears the computer has to ask someone where that name lives. That someone is DNS, and the answer that comes back is an IP address.
The trouble is that the question, in the way the internet grew up, came with no way to check who was answering. Whoever manages to be heard first, or to slip a false answer into a provider's cache, sends the traffic wherever they like — and never has to get into your site at all.
The visitor sees your name in the address bar. The server on the other end is not yours.
What DNSSEC adds
DNSSEC signs the answers. Every record in your zone comes with a cryptographic signature, produced with a private key that stays on the authoritative servers; anyone can verify it with the matching public key.
The check does not stop there. Your domain's public key is itself vouched for by the extension's registry, which is vouched for by the root of the DNS. It is a chain: if one link does not add up, the answer is discarded instead of used.
The practical result is easy to state: a forged DNS answer is not accepted, because whoever produced it does not hold the key to sign it.
What DNSSEC does not do
Worth saying plainly, because this is the common confusion.
DNSSEC encrypts nothing. DNS queries stay readable: it guarantees the authenticity of the answer, not the privacy of the question. And it does not protect the content of the site or what a visitor types into a form — that is the SSL certificate's job.
The two answer different questions. DNSSEC says "you arrived at the right place". SSL says "what you are saying to each other is nobody else's business". Having only one leaves half the journey uncovered.
How to switch it on
If the domain is registered with ICBS and uses our DNS, switching it on is one control in the panel. We generate the keys, sign the zone and send the DS records to the extension's registry; key rollovers happen without you having to notice.
If the DNS belongs to another provider, they generate the keys: they will give you DS records to enter in the ICBS panel, and we pass them to the registry.
Either way there is nothing to pay: DNSSEC is included in the price of the domain.