What DNSSEC does
DNSSEC (DNS Security Extensions) signs your DNS records with keys published as DNSKEY records and builds a chain of trust up to the root zone. A validating resolver rejects any answer whose signature does not check out.
How to read your result
Nattvakt reports a pass when DNSKEY records are present and the answer is authenticated (the resolver's AD flag is set). Keys present but not validated shows as a warning; no keys means DNSSEC is off.
Turning DNSSEC on
Enable signing at your DNS host, then publish the resulting DS record at your registrar to complete the chain of trust.
A DS record without matching keys — or keys without a DS record — breaks resolution, so change them in the right order.
Frequently asked questions
What is DNSSEC?
A set of DNS extensions that sign records cryptographically so resolvers can verify answers were not forged or tampered with in transit.
What is the difference between DNSKEY and DS?
DNSKEY holds the signing keys inside your zone; the DS record at your registrar links your zone to its parent, completing the chain of trust.
Will DNSSEC break my site?
Only if misconfigured — for example a DS record that does not match your keys. Enable signing first, then publish the matching DS record.