DNSSEC

DNSSEC is the abbreviation for 'Domain Name System Security Extensions'. It is a set of extensions to the domain name system (DNS), basically to allow clients to verify the authenticity and integrity of DNS records.

For a domain to make use of DNSSEC, the following is needed: 

 You may have a look at Wikipedia or this short tutorial as starters for reading more about these topics.

 

DNSSEC Support at Joker.com

Joker.com enables you to activate and configure DNSSEC for nearly all of your domains - most domain types (TLDs) do support DNSSEC. The only exceptions at Joker.com currently are .ws and .cn.

Please note: Joker.com supports DNSSEC with standard Joker.com name servers as well as with domains that use external name servers

To find out if your domain is working properly with DNSSEC, you may use the DNSSEC Analyzer.

 Resellers will find similar commands to operate DNSSEC using DMAPI and RPanel.

How To use DNSSEC with a Joker.com Domain and a DNS Hosting Provider

This is about:

To make this work, the domain has to be "linked" to the external name service:

1. Set up the DNS zone and records at the DNS hosting provider

Each DNS hosting provider has its own web interface and system for adding records. Here you have to create the zone records you need, like A records to add IPv4 addresses to a hostname.

2. Still at the DNS hosting provider

sign the domain with DNSSEC. This of course requires, that your DNS provider support DNSSEC.

The end result is that you have a signed domain with a DS record. You will need this information (DS record) later at Joker.com.

3. At Joker.com

Change the name servers for the domain to point to the name servers of the DNS hosting provider.

It should look like this now:

change name servers

This change may take some time to propagate through the larger DNS infrastructure. Until the name server change has fully propagated, people may still see DNS records coming from the previous name servers.

At this point, you have a domain signed with DNSSEC at the DNS hosting provider, and you have changed the records at Joker.com to point to the name servers of the DNS hosting provider. 

Almost done!

If you now run your domain through the DNSSEC analyzer tool, you will still see a problem: "No DS records found"

This means, you still have to create a so-called Delegation Signer (DS) record at Joker.com.

4. Create DS record at Joker.com

change name servers

change name servers

5. Finally, verify that DNSSEC works

using a tool such as Verisign Labs’ DNSSEC Analyzer. It should show nice green check marks now - but please keep in mind, that your changes will take some time until they become active.

Having followed these steps, you have DNSSEC working on a domain registered with Joker.com, using name servers from an external name service provider.

Meanwhile, there is good news: You now also are able to use DNSSEC with the regular Joker.com name servers as well, free of charge! This of course is probably much simpler for you, since you do not have to maintain external name server records, and you can make use of DNSSEC fully integrated into Joker.com's web portal.


Revision #12
Created 30 June 2023 12:15:09 by Admin
Updated 29 September 2023 14:46:11 by Administrator