What we publish

dnssec.me publishes practical DNSSEC material: what DNSSEC is and how the chain of trust works, registrar- and platform-specific enablement guides, and troubleshooting for the failures people actually hit — SERVFAIL, validation failures, broken sites after a key rollover.

How we research

DNSSEC is precisely specified, so we work from primary sources: the relevant RFCs (notably RFC 4033 to 4035 and the DS/algorithm registries), IANA registries, root-zone and registry operator documentation, and the published documentation of the registrars and DNS providers we write guides for. Where resolver behaviour differs between implementations — and with DNSSEC it frequently does — we say so instead of generalising.

We test the instructions

Platform guides describe the steps as they appear in the provider's own interface. Provider UIs change without notice, so if a guide no longer matches what you see, that is a bug on our side and we want to hear about it. Where a step depends on the registrar rather than the DNS host, we say which is which — that distinction causes more failed DNSSEC rollouts than anything else.

Honesty about risk

DNSSEC can take a domain offline if it is misconfigured: a mismatched DS record makes a zone fail validation and resolvers will refuse to answer. Our guides state that risk plainly, tell you how to verify before and after, and explain how to back out. We would rather you delay a rollout than break a production domain because a guide sounded easy.

Accuracy and corrections

If we publish something inaccurate, we fix it. Material corrections — anything that changes the meaning or the instruction — are made promptly and noted on the page rather than quietly edited. Minor fixes are made without a note. Spotted an error, or a provider UI that has moved? Email [email protected] with the URL and what you saw. Corrections from practitioners are genuinely welcome and are the fastest way this site improves.

Use of AI

We may use AI tools to help draft, outline or edit. AI is never the final authority: a person is responsible for every published page, checks its technical claims against the standards, and stands behind it. We do not publish unreviewed machine-generated text.

Independence and no invented numbers

We name specific registrars, DNS providers and third-party validators (Verisign DNSSEC Analyzer, DNSViz, Google's dig toolbox) because they are the tools that do the job. We are not paid to recommend any of them, and we do not publish statistics, adoption figures or credentials we cannot substantiate.

Related: About · Insights · Accessibility