1000 FAQs, 500 tutorials and explanatory videos. Here, there are only solutions!
Securing Web traffic with DNSSEC
This guide explains what DNSSEC is and how this protection enhances the security of Domains at Infomaniak and the traffic they generate.
What is DNSSEC for?
Each URL corresponds to an IP address, and when a user enters your site's URL into their web browser, it calls on a DNS server whose role is to redirect them to the IP address that corresponds to the entered domain (technically, this is called DNS resolution).
When DNSSEC is not enabled on your domain name, a malicious person could detect a vulnerability in a DNS server and change the correspondence between your domain name and the IP address of your site to an IP of their choice. In such a scenario, the user entering your site's URL would be redirected to another website that does not match the content of your website.
DNSSEC secures the authenticity of the response provided by the DNS server, thus ensuring to users that they are actually accessing the website they intend to visit. If a hacker tries to modify the IP address of your domain name in a DNS server protected by DNSSEC during resolution, the server would reject their requests since they wouldn't be authenticated.
DNSSEC is therefore an additional security layer to a site's SSL certificate. DNSSEC ensures that users are directed to the website corresponding to the entered URL, and the SSL certificate comes into play to encrypt the exchanges between the user's web browser and the web server of the site they are visiting.
Enable DNSSEC
DNSSEC is available and already activated for the vast majority of domain name extensions at the time of purchase.
If necessary, it can be activated in a few clicks for fully managed domain names at Infomaniak:
- log in to the Infomaniak Manager (manager.infomaniak.com) from a web browser like Brave or Firefox
- click on the icon at the top right of the interface (or navigate using the left side menu, for example)
- choose Domains (universe Web & Domain)
- click on the name of the relevant object in the displayed table
- enable DNSSEC from the Domain Dashboard:
If the DNS zone for your domain is managed by another registrar, you will need to provide technical information provided by them. If the information entered is incorrect, your domain name will no longer be accessible. Therefore, we recommend transferring the complete management of your domain to Infomaniak before enabling DNSSEC if you are not familiar with these procedures.
Check if DNSSEC is enabled
The propagation of DNSSEC with the registry can take several hours before it becomes effective.
Enter the domain name to check on this analysis site.