Enable DNSSEC for an existing zone

You use Control Center to enable DNSSEC. The steps you need to complete depend on the DNSSEC option you are using.

If you presently sign your zones and would like to use the “sign and serve” option, continuous signing is not supported. Before configuring the zone on Control Center, you must:

  • remove the existing delegation signer (DS) record.
  • wait out the time to live (TTL) for the DS record.

Continue with the instructions for the type of DNSSEC you're configuring: