To Update the DNSSEC Configuration on your Zone
1.  Click Overview or Manage DNS. Main menu bar
2.  Click Manage in the far right column.
3.  Click Zone Options on the menu bar. Zone Options Tab
4.  Click DNSSEC on the sub-menu bar. DNSSEC Tab in Zone Options
5.  Use the following information to update the DNSSEC form:Add a New Zone Signing Key – Click to add another encryption method. RSA/SHA-1 is required. 256, 512, and DSA methods are optional.

Add a New Key Signing Key – Click to add another encryption method. RSA/SHA-1 is required. 256, 512, and DSA methods are optional.

Download .txt format – Delegation Signer Records – Click to download a text file of the DS records. These are sent to your domain registrar to update your domain records.

Download .txt format – DNS Key Signing Key Public Key Records – Not used in the current DNSSEC setup. Field supports some legacy configurations.

Download .txt format – DNS Zone Signing Key Public Key Records – Not used in the current DNSSEC setup. Field supports some legacy configurations.

Update DNSSEC
6. Use the following information to make selections in the Actions column drop-down boxes.Actions: Select Rollover or Rollover Now to set the overlap time between the creation of a new key and the expiration of the old key during the Rollover process.

  • Rollover: Set the key to expire after the configured overlap time of one week.
  • Rollover Now: Set the key to expire immediately. There will be no overlap between the new key and the expired key.
    NOTE: This could cause problems for users because registrars will expect a different expiration time.
DNSSEC Actions Options
7. Click View task timeline to open a view into the DNSSEC expiration dates and timelines. DNSSEC Task View
8.  Click Update DNSSEC to complete the DNSSEC changes. Update DNSSEC button