DNSSEC cryptographically signs your DNS records. Protects visitors from DNS cache-poisoning attacks. Free on every AmzHost domain.
Enable (domain registered with us)
- Portal → Domains → Select domain → DNSSEC.
- Click Enable DNSSEC.
- We generate KSK + ZSK, publish DS records to the registry automatically.
- Takes 1–24 hours to activate at the TLD level.
Enable (domain at another registrar, DNS with us)
Generate the DS record from our DNSSEC page, then paste it into the registrar’s DNSSEC config. Keep KSK rollovers coordinated — we handle automatic key rotation if both registrar and DNS are with us.
Verify
dig +dnssec amzhost.pk | grep RRSIG
# should print RRSIG records