Knowledge BaseDomains & DNSEnable DNSSEC signing

Enable DNSSEC signing

Domains & DNS 3 min read Updated March 2026

DNSSEC cryptographically signs your DNS records. Protects visitors from DNS cache-poisoning attacks. Free on every AmzHost domain.

Enable (domain registered with us)

  1. Portal → Domains → Select domain → DNSSEC.
  2. Click Enable DNSSEC.
  3. We generate KSK + ZSK, publish DS records to the registry automatically.
  4. Takes 1–24 hours to activate at the TLD level.

Enable (domain at another registrar, DNS with us)

Generate the DS record from our DNSSEC page, then paste it into the registrar’s DNSSEC config. Keep KSK rollovers coordinated — we handle automatic key rotation if both registrar and DNS are with us.

Verify

dig +dnssec amzhost.pk | grep RRSIG
# should print RRSIG records

Was this article helpful?

Still stuck?

Our team answers tickets 24/7. Median first response: 15 minutes.