Defaults.Exposed

Defaults.Exposed › Setup › DNSSEC

How to set up DNSSEC on Reg.ru

Enable DNSSEC at Reg.ru so no one can forge your DNS answers and redirect your visitors or email.

Why this matters to your business

Every time someone opens your website or emails you, their computer asks the DNS system where to find you. Those answers usually travel unsigned, so an attacker who can interfere with the lookup can silently send your visitors to a counterfeit site or reroute your email to their own server — all while your genuine domain still appears in the address bar.

DNSSEC shuts that door. It cryptographically signs your DNS answers, so anyone looking you up can confirm the answer really came from you and was not tampered with along the way. In plain terms: it prevents domain hijacking and cache poisoning, the attacks that weaponise your own domain against your customers.

What Reg.ru requires before you can switch it on

Reg.ru’s DNSSEC page sets out three conditions:

Also worth knowing what DNSSEC is not: Reg.ru’s own page stresses it does not protect against DDoS attacks, does not make your traffic confidential, and does not encrypt your website — it only authenticates DNS answers.

The real risk — do this in order

DNSSEC can take your domain offline if it is set up or removed in the wrong order. The classic failure is moving your DNS to a different host (or switching off signing) without first removing the signing keys from the registry — stale keys keep demanding signatures that no longer exist, and lookups fail.

So: if you ever move DNS away from Reg.ru’s nameservers, disable DNSSEC first, then move.

Step-by-step on Reg.ru (domain on ns1.reg.ru / ns2.reg.ru)

  1. Sign in to your Reg.ru personal account (личный кабинет).
  2. Open the «Домены» (Domains) section and click the row with your domain.
  3. Make sure the «Премиум DNS» (Premium DNS) service is active for the domain — order it first if not.
  4. In the «DNS-серверы и управление зоной» (DNS servers and zone management) block, click «Изменить» (Edit).
  5. On the «Управление» (Management) tab, find the DNSSEC field — it shows the current status.
  6. Switch the toggle on and confirm. Reg.ru signs the zone and lodges the keys with the registry for you; the change applies within minutes.

Step-by-step when your DNS is hosted elsewhere

If Reg.ru is your registrar but another company hosts (and signs) your DNS:

  1. Enable DNSSEC at your DNS host first, so the zone is actually signed.
  2. In the Reg.ru domain’s DNSSEC section, use «Добавить ключи» (Add keys). Reg.ru’s help says the DNSKEY records are retrieved from your zone’s authoritative server automatically and passed to the registry — you don’t retype them.
  3. Confirm the status shows DNSSEC as active once the registry accepts the keys.

Reg.ru quirks people get wrong

Verify it worked

Once DNSSEC is switched on (and any keys are lodged), run the free check on this site. It will tell you in plain language whether DNSSEC is correctly published and trusted for your domain.

See the full fix guide →

Done? Check your domain free to confirm it worked — and see your full grade across all 34 checks.