What DNSSEC does
DNSSEC adds cryptographic signatures to DNS responses so resolvers can detect tampering. On NextShopper you enable DNSSEC at the DNS adapter from the domain DNS tab. Portal help states: Signs the zone at the DNS adapter. DS records at the registry are not published from this console.
That limitation matters. Full public DNSSEC validation often also needs DS records at the registry parent. Enabling adapter signing without matching DS—or leaving stale DS after you move nameservers—can make the domain fail to resolve. Only enable DNSSEC when you understand the impact or staff is guiding you.
Who this guide is for
- Domains using NextShopper-hosted DNS nameservers
- Security-conscious owners hardening DNS
- Customers whose checklist asks to “turn on DNSSEC”
Before you start
- Confirm nameservers point at the DNS zone you manage in this portal.
- Do not enable DNSSEC mid-migration between DNS hosts.
- Prefer a maintenance window; have a rollback plan with support.
- Sign in with access to the domain.
Step-by-step: enable DNSSEC
- Open Domains → select the domain → DNS tab.
- Find DNSSEC.
- Read the on-screen help about adapter signing vs registry DS.
- Select Enable DNSSEC.
- Confirm DNSSEC enabled on the DNS adapter. / status Enabled.
- If a partner or auditor requires registry DS, open a Technical ticket with the FQDN and ask staff how DS publication works for your TLD.
After enablement: verify carefully
- Confirm the domain still resolves in major public resolvers.
- Use a DNSSEC checking tool; “insecure” may simply mean DS is unpublished—that matches the console note.
- If resolution breaks, stop and contact support rather than repeatedly toggling.
When you later change nameservers away from this adapter, clean up DNSSEC/DS with the new provider so signatures and DS do not disagree.
What happens next / how to verify success
- Portal shows DNSSEC Enabled.
- Adapter signs the zone going forward.
- Ordinary A/MX/TXT edits continue as usual; DNSSEC signs them.
Common problems
| Problem | What to try |
|---|---|
| Enable fails | Confirm DNS hosting on this adapter; retry; open a ticket |
| Domain stops resolving | Contact support immediately; remove mismatched DS at registry if present |
| Tools say insecure | DS may be unpublished—ask about registry DS |
| Broke after NS change | Revisit DNSSEC at both old and new providers |
| Unsure you need it | Optional for many sites—fix A/MX first |
Frequently asked questions
Is DNSSEC required for email?
No. SPF/DKIM/DMARC TXT records matter more for mail authentication.
Does WHOIS privacy relate to DNSSEC?
No.
Can I disable DNSSEC later?
If a clear disable control is not shown, open a ticket rather than forcing registry mismatches.
Does enabling DNSSEC change my record values?
It signs them; you still manage record data yourself.
Is this the same as SSL?
No. DNSSEC protects DNS; SSL/TLS protects HTTPS after clients find the right host.
Related guides
- How to add, edit, or delete DNS records
- How to change domain nameservers
- How to point a domain to NextShopper hosting
- How to complete DCV DNS for an SSL certificate
Still need help?
For DNSSEC outages or DS publication questions, open a support ticket or Contact with the domain name and whether nameservers are on NextShopper.