DNSSEC is an important layer of security for organisations that have a significant online presence or have customers navigating to their site.
Domain Name System Security Extension (DNSSEC) provides additional online protection for your customers and your brand. Verisign is committed to working with members of the internet community to ensure that DNSSEC is broadly successful. Find out what DNSSEC means for you, how you can prepare for DNSSEC, and how Verisign can help.
Given the trajectory of Secure Sockets Layer (SSL) and similar security initiatives, DNSSEC is a business imperative - driven by internal requirements such as risk management and consumer demand for a safer internet experience.
It increases trust for a multitude of internet activities, including e-commerce, online banking, e-mail, VoIP, online software distribution and video on demand.
DNSSEC helps prevent cyber criminals from diverting website visitors or e-mail messages to imposter sites or addresses, where criminals can potentially extract credit card data and steal user passwords, eavesdrop on Voice over IP (VoIP) communications, and defame brands.
Although DNSSEC enhances DNS security, it is not a comprehensive solution. It does not protect against distributed denial of service (DDoS) attacks, ensure confidentiality of data exchanges, encrypt website data or prevent IP address spoofing and phishing. Other layers of protection, such as DDoS mitigation, security intelligence, Secure Sockets Layer (SSL) encryption and site validation, as well as two-factor authentication, are also critical to making the internet more secure. You should use these mechanisms in conjunction with DNSSEC.
Benefits for Registrants
By implementing DNSSEC, you can:
DNSSEC is based on a hierarchy of trust. Entities at higher levels of the hierarchy vouch for entities below them. This means that the entity that provided your domain name (usually a registrar, ISP, or DNS hosting service) must implement DNSSEC before you can enable it.
To enable DNSSEC for your website or network system (e.g. e-mail), you must digitally sign your domain name information. In most cases, you simply opt-in to this process when you register your domain name. If you have already registered your domain name and then later choose to implement DNSSEC for your zone, usually your DNSSEC-enabled registrar will have a process for modifying zone records after registration.
Registrants can take steps now to reach their goal of a DNSSEC-enabled environment that helps mitigate risk, maintain end-user trust and provide a competitive advantage.
Explore and Educate
Evaluate
Get Involved
Work within your industry to encourage DNSSEC adoption and help develop DNSSEC best practices and approaches that meet the needs of your organisation.