What does DNSSEC do?
DNSSEC (DNS Security Extensions) adds a digital signature to DNS records. It protects against DNS spoofing / cache poisoning: attacks in which a malicious party injects false DNS responses so that users are sent to a fake server instead of the real one.
Without DNSSEC: the browser asks “where is example.com?” → the answer can be forged With DNSSEC: the answer is cryptographically verified → forgery is detected
Why is it not immediately necessary for an ordinary website?
1. HTTPS/TLS already does the heavy lifting Most websites use HTTPS with a valid SSL certificate. Even if an attacker uses DNS spoofing to redirect traffic to their server, they cannot imitate your domain’s TLS certificate. The browser then shows a certificate error, and the attack visibly fails.
2. Attacks are complex at infrastructure level DNS cache poisoning requires access to a vulnerable resolver (ISP level or higher). It is not an attack an ordinary hacker can simply carry out. Moreover, large DNS providers (Cloudflare, Google) actively harden their resolvers.
3. Low adoption = limited benefit Validation only works if the user uses a DNSSEC-validating resolver. Far from all ISPs and corporate networks do this. Even a perfectly signed domain offers no protection if the resolver never checks the signature.
4. Management complexity DNSSEC introduces key management (ZSK/KSK), key rollovers and a larger DNS payload. A misconfiguration or a forgotten key rollover can make your domain completely unreachable. For small sites, the risk of misconfiguration sometimes outweighs the security gain.
When does DNSSEC make sense?
| Situation | Relevance |
|---|---|
| Financial / banking services | High — phishing via DNS is a real risk |
| Government domains (.be, .nl mandatory) | Mandatory or strongly recommended |
| API endpoints without TLS pinning | Definitely worth considering |
| Mail servers (MX + DANE/TLSA) | Significant added value for email security |
| Ordinary WordPress website with HTTPS | Low – TLS already covers the biggest risk |
In summary
DNSSEC protects the DNS layer itself, but for most websites HTTPS already provides the vast majority of the protection that DNSSEC would add. It is a “defence in depth” measure: worthwhile if your infrastructure supports it and you can handle the management overhead, but certainly not an urgent priority for a standard WordPress hosting environment such as Kyzoe.be.
Would you still like to enable it? Send us an email and we will do it for you. Please bear in mind that an activation request can take up to 48 hours.
Read also
A website of your own for your cultural organisation: web hosting with 50% off
Do you work in culture? Then Kyzoe gives you 50% off web hosting or WordPress hosting in the first year and 33%…
Read moreNovamira: an AI agent working directly in your WordPress site
With Novamira, an AI agent such as Claude or Cursor works directly in WordPress. What it can do, what Pro adds, how…
Read moreUpdates to our hosting panel in September 2026
Four Enhance updates in September 2026: faster disk usage, Roundcube 1.6.18, LiteSpeed 6.3.7, custom DNS resolvers and more reliable migrations from cPanel…
Read more


