| Note: Some TLDs, such as Dot.BS , are not currently supported for DNSSec management. |
Domain Name System Security Extensions (DNSSEC) are designed to protect against forged and manipulated DNS data (such as DNS spoofing or cache poisoning). It ensures that the DNS records your visitors receive are identical to the authentic records published on your authoritative DNS server.
How Does DNSSEC Work?
DNSSEC works by digitally signing DNS lookup records using public-key cryptography:
- The correct DNSKEY record is authenticated via a chain of trust, starting from verified public keys at the DNS root zone.
- A validating DNS resolver checks the digital signature to confirm the information is identical (unmodified and complete) to what was published by the domain owner.
- DNSSEC protects all records within the zone, including
A,AAAA,MX,TXT, andCNAMErecords.
How to Set Up DNSSEC at Rebel
Rebel acts as your domain registrar to submit Delegation Signer (DS) records directly to top-level registries (such as CIRA for
.CA or Verisign for .COM).Option 1: Using an External DNS Provider
If you manage your DNS through a third-party host (e.g., Cloudflare, Route 53, or an enterprise DNS provider), complete the following steps:
- Enable DNSSEC at your DNS provider to sign your zone and generate your Delegation Signer (DS) records.
- Copy the four DS parameters provided by your DNS host.
- Submit the required parameters to Rebel Support from an authorized email address.
Required Support Submission Parameters
To request manual DNSSEC activation, please email Rebel Support with the following completed information:
Domain Name: [yourdomain.tld]
Key Tag: [e.g., 2371]
DNSKEY Algorithm: [e.g., 13 (ECDSA Curve P-256 with SHA-256)]
Digest Type: [e.g., 2 (SHA-256)]
Key Digest: [e.g., 4B2A... full hex string]
Option 2: Using Plesk Hosting DNS
Plesk allows you to manage and sign your DNSSEC records directly within your hosting control panel. Follow Plesk's DNSSEC Management Guide to generate your DS keys, then email the generated parameters above to Rebel Support to complete registry delegation.
Account Security & Operational Details
- Account Security Verification: For security reasons, your implementation request and DS parameters must be sent directly from the Primary or Alternate email address listed on your Rebel account. For safety, Rebel cannot apply registry-level security records from unauthorized email addresses.
- Turnaround & Submission SLA: Submitting DS records to the registry takes under 5 minutes for our senior domain specialists to execute once authorized.
- Registry Propagation: Global DNSSEC propagation for validating resolvers following registry update takes 1 to 5 hours.
- Backout / Rollback Process: If you need to disable or roll back DNSSEC, submit a removal request from your account email. Removing the DS record at the registry takes under 5 minutes on our end, with full removal propagating globally within 1 to 5 hours.
| Note: It can take up to 48 hours for your application to be processed. Additional time may be required for DNS propagation as well, though this timeframe varies depending on the company. |
Comments
0 comments
Please sign in to leave a comment.