Enable “sign and serve” DNSSEC for an existing zone

How to

  1. Go to > DNS SOLUTIONS > Edge DNS.
  2. On the Zone list page, click the name of the zone you’d like to edit.
  3. Expand the Zone settings section.
  4. Select the DNSSEC Sign and Serve checkbox, and select a DNSSEC algorithm.
    The current recommended algorithm is ECDSA-P256-SHA256. Select RSA SHA-256 if you want to avoid the use of ECDSA.
  5. For secondary zones, select a TSIG key or create a new one.
  6. Click Add to change list.
    Note: You must review and submit your change list per Review the change list before any changes propagate.