Domains

DNSSEC: the signature that proves the domain is yours

Without DNSSEC an attacker can answer in your domain's place and send your visitors somewhere else, without ever touching your site. With DNSSEC that answer gets thrown away.

  • Redirect setup
  • Anycast DNS
  • DNS management
  • DNSSEC
  • WordPress Micro Hosting
  • 3 custom email addresses
  • SSL certificate
  • Unlimited subdomains

What DNS does, and why it is a target

When somebody types your domain into a browser, before any page appears the computer has to ask someone where that name lives. That someone is DNS, and the answer that comes back is an IP address.

The trouble is that the question, in the way the internet grew up, came with no way to check who was answering. Whoever manages to be heard first, or to slip a false answer into a provider's cache, sends the traffic wherever they like — and never has to get into your site at all.

The visitor sees your name in the address bar. The server on the other end is not yours.

What DNSSEC adds

DNSSEC signs the answers. Every record in your zone comes with a cryptographic signature, produced with a private key that stays on the authoritative servers; anyone can verify it with the matching public key.

The check does not stop there. Your domain's public key is itself vouched for by the extension's registry, which is vouched for by the root of the DNS. It is a chain: if one link does not add up, the answer is discarded instead of used.

The practical result is easy to state: a forged DNS answer is not accepted, because whoever produced it does not hold the key to sign it.

What DNSSEC does not do

Worth saying plainly, because this is the common confusion.

DNSSEC encrypts nothing. DNS queries stay readable: it guarantees the authenticity of the answer, not the privacy of the question. And it does not protect the content of the site or what a visitor types into a form — that is the SSL certificate's job.

The two answer different questions. DNSSEC says "you arrived at the right place". SSL says "what you are saying to each other is nobody else's business". Having only one leaves half the journey uncovered.

How to switch it on

If the domain is registered with ICBS and uses our DNS, switching it on is one control in the panel. We generate the keys, sign the zone and send the DS records to the extension's registry; key rollovers happen without you having to notice.

If the DNS belongs to another provider, they generate the keys: they will give you DS records to enter in the ICBS panel, and we pass them to the registry.

Either way there is nothing to pay: DNSSEC is included in the price of the domain.

What changes with DNSSEC on

Four things, all covered by the price of the domain.

Answers arrive signed

Every DNS answer for your domain carries a cryptographic signature. Whoever receives it can check that it really came from your servers and that nobody altered it on the way.

It closes DNS spoofing

That is the attack where somebody answers ahead of the legitimate server, or poisons a provider's cache, to divert visitors to a server that is not yours. An answer without a valid signature is discarded.

It protects the mail too

Hijacking is not only about the website: MX records say where your email goes. Signing the zone protects the path your messages take, not just the path to your pages.

It goes on with a switch

With ICBS DNS you do not have to generate keys or send anything to the registry: switching it on from the panel does all of it, keys included, and rolls them when needed.

Where it works, and on what terms

Availability

  • Extensions that support it466 of 491
  • CostIncluded with the domain
  • ActivationFrom the panel, immediate

Requirements

  • Domain registered with ICBS
  • DNS managed by ICBSRecommended
  • External DNSPossible, with your provider's records

Frequently asked questions about DNSSEC

No. It is covered by the price of the domain, along with Anycast DNS, the SSL certificate and the mailboxes. There is no separate fee and no activation charge.
On nearly all of them: 466 of the 491 extensions we sell support it, including .it, .com, .net, .org and .eu. Each extension page says whether it is available. Where it is not, that is the extension's registry, not us.
Not noticeably. Checking the signature adds a few milliseconds to the first lookup, then the answer sits in cache like any other. On a page that takes hundreds of milliseconds to load, it is not a difference you can see.
Yes. If the DNS is not ours, your provider generates the keys and gives you the DS records: you enter them in the ICBS panel and we pass them to the registry. The manual step exists only in this case.
No, and the two do not overlap. DNSSEC makes sure the address you reach is the right one; the SSL certificate protects what you exchange once you are there. You want both, and at ICBS both come with the domain.
The real risk is turning it off badly, or changing DNS while leaving the old DS records with the registry: the domain then becomes unreachable for anyone who checks signatures. If you switch it on from the panel with our DNS, that case does not arise, because we handle the sequence.

Have a project in mind?

Let's talk: we'll help you choose the right solution, with no obligation.