DNSSEC (Domain Name System Security Extensions) adds cryptographic signatures to your DNS so resolvers can verify the answers are genuine and haven't been tampered with. It helps protect against DNS spoofing.
Enabling it has two parts:
- Generate the DNSSEC keys (the DS record) where your DNS zone is hosted.
- Publish that DS record at your domain's registrar so the parent zone trusts your signatures.
In WHM-based setups, DNSSEC keys are managed under the DNS zone tools; cPanel users may see a DNSSEC option in Zone Editor on supported servers. Because the exact steps depend on where your nameservers and registrar live, the safest path is to open a ticket. Tell us your domain and we'll generate the DS record and help you add it at the registrar. Both halves must match or your domain can stop resolving.