DNS is the quiet system that turns your domain name into the address a browser or mail server actually connects to. It works so invisibly that most business owners never think about it — until it is attacked. DNSSEC is the protection that stops one of the nastier attacks on that system. Here is what it does, in plain language, and how to decide whether your business needs it.
This is part of the domain-security work we do through DNS Shield.
The problem DNSSEC solves
When someone visits your website or sends you email, their device asks the DNS system, “where do I find this domain?” The trouble is that, by default, the answer that comes back is not verified. An attacker who can tamper with that answer — through what is called DNS spoofing or cache poisoning — can silently send your visitors and emails to a server they control instead of yours. To the visitor, nothing looks wrong; they typed your address and got a convincing fake. It is a quiet, dangerous attack precisely because nobody notices it happening.
What DNSSEC actually does
DNSSEC adds a digital signature to your DNS records, creating a chain of trust that lets the asking device verify the answer genuinely came from the real owner of the domain and was not altered along the way. If an answer has been tampered with, the signature does not match, and it is rejected. In effect, DNSSEC is a tamper-proof seal on the directions to your domain — it does not hide anything, it proves authenticity. South Africa’s own .za namespace supports it under a published policy, so it is available for local domains.
What DNSSEC is not
It helps to be clear about its limits. DNSSEC protects the integrity of DNS answers; it does not encrypt your traffic (that is what HTTPS does), it does not stop spam or phishing (that is what SPF, DKIM, and DMARC do), and it is not a firewall. It is one specific, important layer — making sure people reach the real you — not a complete security solution on its own. The strongest setups use it alongside those other protections, not instead of them.
How it actually gets switched on
Enabling DNSSEC is a two-part handshake. Your DNS provider signs your zone and generates a small record called a DS (Delegation Signer) record; that DS record then has to be published with your domain registrar, which passes it up to the registry — for local domains, the .za registry. Only when both halves are in place does the chain of trust connect from the registry all the way down to your records. That two-sided dependency is exactly why it pays to have it done carefully: if the signed zone and the registrar record ever fall out of step — during a DNS migration, say, or a routine key rollover — validating resolvers will reject your domain outright, and the site and email go dark until it is fixed. Set up and maintained properly it is reliable; it is simply unforgiving of half-finished changes.
Does your business need it?
The honest answer is “it depends on what you would lose if your domain were hijacked.” For a business that handles payments, logins, sensitive customer data, or where being impersonated would do real reputational damage, DNSSEC is a sensible, low-cost layer well worth enabling. For a simple brochure site, it is good practice but lower priority than getting your email authentication and HTTPS right first. The cost is small; the main requirement is that it be configured correctly, because a botched DNSSEC setup can take your domain offline — which is exactly why it is worth having someone who knows the system handle it.
The practical next step
If you are not sure whether DNSSEC is enabled on your domain — or whether the rest of your DNS and email security is in order — a short review will show exactly what is configured and what is exposed. For the email side of the same picture, see our DNS and email security playbook.
Published 16 June 2026. Last updated 16 June 2026.