Defaults.Exposed › Setup › DNSSEC
How to set up DNSSEC on Reg.ru
Enable DNSSEC at Reg.ru so no one can forge your DNS answers and redirect your visitors or email.
Why this matters to your business
Every time someone opens your website or emails you, their computer asks the DNS system where to find you. Those answers usually travel unsigned, so an attacker who can interfere with the lookup can silently send your visitors to a counterfeit site or reroute your email to their own server — all while your genuine domain still appears in the address bar.
DNSSEC shuts that door. It cryptographically signs your DNS answers, so anyone looking you up can confirm the answer really came from you and was not tampered with along the way. In plain terms: it prevents domain hijacking and cache poisoning, the attacks that weaponise your own domain against your customers.
What Reg.ru requires before you can switch it on
Reg.ru’s DNSSEC page sets out three conditions:
- The domain must be delegated to
ns1.reg.ru/ns2.reg.ru. The hosting nameservers (ns1.hosting.reg.ru,ns2.hosting.reg.ru,ns5.hosting.reg.ru,ns6.hosting.reg.ru) do not support DNSSEC. - The paid «Премиум DNS» (Premium DNS) service must be active for the domain — DNSSEC at Reg.ru is a feature of that service, not of the free DNS.
- The TLD must be supported. At the time Reg.ru’s help was last checked, the list was .ru, .su, .рф, .com, .net, .name — with a note that the list will be expanded. If your domain is in another zone, confirm current support in your Reg.ru console.
Also worth knowing what DNSSEC is not: Reg.ru’s own page stresses it does not protect against DDoS attacks, does not make your traffic confidential, and does not encrypt your website — it only authenticates DNS answers.
The real risk — do this in order
DNSSEC can take your domain offline if it is set up or removed in the wrong order. The classic failure is moving your DNS to a different host (or switching off signing) without first removing the signing keys from the registry — stale keys keep demanding signatures that no longer exist, and lookups fail.
So: if you ever move DNS away from Reg.ru’s nameservers, disable DNSSEC first, then move.
Step-by-step on Reg.ru (domain on ns1.reg.ru / ns2.reg.ru)
- Sign in to your Reg.ru personal account (личный кабинет).
- Open the «Домены» (Domains) section and click the row with your domain.
- Make sure the «Премиум DNS» (Premium DNS) service is active for the domain — order it first if not.
- In the «DNS-серверы и управление зоной» (DNS servers and zone management) block, click «Изменить» (Edit).
- On the «Управление» (Management) tab, find the DNSSEC field — it shows the current status.
- Switch the toggle on and confirm. Reg.ru signs the zone and lodges the keys with the registry for you; the change applies within minutes.
Step-by-step when your DNS is hosted elsewhere
If Reg.ru is your registrar but another company hosts (and signs) your DNS:
- Enable DNSSEC at your DNS host first, so the zone is actually signed.
- In the Reg.ru domain’s DNSSEC section, use «Добавить ключи» (Add keys). Reg.ru’s help says the DNSKEY records are retrieved from your zone’s authoritative server automatically and passed to the registry — you don’t retype them.
- Confirm the status shows DNSSEC as active once the registry accepts the keys.
Reg.ru quirks people get wrong
- It’s a paid add-on. Unlike registrars that bundle DNSSEC for free, at Reg.ru it comes with the «Премиум DNS» service. Budget for that or keep DNSSEC at an external DNS host.
- Hosting nameservers don’t do DNSSEC. If your domain sits on
ns*.hosting.reg.ru, the toggle isn’t available — move the zone tons1.reg.ru/ns2.reg.ru(mind the migration) or sign at an external DNS host. - Check your TLD is on the list. Only a handful of zones (.ru, .su, .рф, .com, .net, .name at last check) are supported; others may fail even with Premium DNS active.
- Don’t double-sign. If an external DNS host already signs your zone, you only lodge its keys via «Добавить ключи» — you don’t also enable Reg.ru’s own signing.
- Disable DNSSEC before changing nameservers. Switching DNS hosts with stale keys still lodged at the registry is the classic way to knock a domain offline.
- Give it time. Enabling applies within minutes, but full propagation of DNSSEC changes can take up to a day.
Verify it worked
Once DNSSEC is switched on (and any keys are lodged), run the free check on this site. It will tell you in plain language whether DNSSEC is correctly published and trusted for your domain.
Done? Check your domain free to confirm it worked — and see your full grade across all 34 checks.