Enable “sign and serve” DNSSEC for an existing zone
- Go to .
- On the Zone list page, click the name of the zone you’d like to edit.
- Expand the Zone settings section.
Select the DNSSEC Sign and Serve
checkbox, and select a DNSSEC
The current recommended algorithm is ECDSA-P256-SHA256. Select RSA SHA-256 if you want to avoid the use of ECDSA.
- For secondary zones, select a TSIG key or create a new one.
Click Add to change list.
Note: You must review and submit your change list per Review the change list before any changes propagate.