Personal support from Ostend   support@kyzoe.be   +32 59 53 00 00

DNSSEC: what it is and why it isn’t always urgent

DNSSEC: what it is and why it isn’t always urgent

What does DNSSEC do?

DNSSEC (DNS Security Extensions) adds a digital signature to DNS records. It protects against DNS spoofing / cache poisoning: attacks in which a malicious party injects false DNS responses so that users are sent to a fake server instead of the real one.

Without DNSSEC: the browser asks “where is example.com?” → the answer can be forged With DNSSEC: the answer is cryptographically verified → forgery is detected


Why is it not immediately necessary for an ordinary website?

1. HTTPS/TLS already does the heavy lifting Most websites use HTTPS with a valid SSL certificate. Even if an attacker uses DNS spoofing to redirect traffic to their server, they cannot imitate your domain’s TLS certificate. The browser then shows a certificate error, and the attack visibly fails.

2. Attacks are complex at infrastructure level DNS cache poisoning requires access to a vulnerable resolver (ISP level or higher). It is not an attack an ordinary hacker can simply carry out. Moreover, large DNS providers (Cloudflare, Google) actively harden their resolvers.

3. Low adoption = limited benefit Validation only works if the user uses a DNSSEC-validating resolver. Far from all ISPs and corporate networks do this. Even a perfectly signed domain offers no protection if the resolver never checks the signature.

4. Management complexity DNSSEC introduces key management (ZSK/KSK), key rollovers and a larger DNS payload. A misconfiguration or a forgotten key rollover can make your domain completely unreachable. For small sites, the risk of misconfiguration sometimes outweighs the security gain.


When does DNSSEC make sense?

Situation Relevance
Financial / banking services High — phishing via DNS is a real risk
Government domains (.be, .nl mandatory) Mandatory or strongly recommended
API endpoints without TLS pinning Definitely worth considering
Mail servers (MX + DANE/TLSA) Significant added value for email security
Ordinary WordPress website with HTTPS Low – TLS already covers the biggest risk

In summary

DNSSEC protects the DNS layer itself, but for most websites HTTPS already provides the vast majority of the protection that DNSSEC would add. It is a “defence in depth” measure: worthwhile if your infrastructure supports it and you can handle the management overhead, but certainly not an urgent priority for a standard WordPress hosting environment such as Kyzoe.be.

Would you still like to enable it? Send us an email and we will do it for you. Please bear in mind that an activation request can take up to 48 hours.

Read also

Need help with your website or hosting?

Ask your question, we will help you personally.

EN