Return to blog
ToolsDNSSECCloudflareRegistro.brDS record

How to configure DNSSEC on the Registro.br using the Cloudflare

DNSSEC adds cryptographic validation to domain DNS responses. If your domain is on Registro.br and uses Cloudflare nameservers, the flow is: activate DNSSEC on Cloudflare, copy the record D.S.generated and publish this DS in Registro.br.

Published in Matheus Henrique10 min reading

Quick Summary

When to use DNSSEC with Cloudflare and Registro.br

Use this guide when the domain is already delegated to Cloudflare and you want to enable DNSSEC to secure the DNS resolution chain. Cloudflare signs the zone and generates DS data; Registro.br publishes this DS at the domain level .br.

Who signs the zone
Cloudflare
Where does DS publish
Registro.br
Validation
dig / DNSViz

Before you start

DNSSEC is a sensitive configuration. If the DS published in Registro.br does not match the key in Cloudflare, resolvers that validate DNSSEC may fail to resolve the domain.

  • Confirm that the domain is already active on Cloudflare.
  • Confirm that the nameservers on Registro.br are the nameservers on Cloudflare.
  • Remove or replace old DS if the domain already used DNSSEC on another provider.
  • Use only the DNSSEC values generated for the specific domain in the Cloudflare dashboard.

Step by step

  1. 01

    Confirm the domain nameservers

    Before enabling DNSSEC, check whether the domain already responds to the Cloudflare nameservers:

    dig NS exemplo.com.br +short

    The response should show the two nameservers assigned by Cloudflare for the domain.

  2. 02

    Enable DNSSEC on the Cloudflare

    On the Cloudflare panel, select the domain, access the DNS and open settings. In the option DNSSEC, click to enable. The Cloudflare will sign the zone and display the data necessary to create the DS record in the registrar.

  3. 03

    Copy DS record data

    On the Cloudflare DNSSEC card, copy the DS record values. The most common fields are:

    • Key Tag: numeric key identifier.
    • Algorithm: algorithm used by the key.
    • Digest Type: type of the cryptographic digest.
    • Digest: long summary value.
  4. 04

    Access the domain at Registro.br

    Access Registro.br, log in to the domain's owner or administrative account and select the domain that uses Cloudflare.

  5. 05

    Register the DS of Cloudflare on Registro.br

    In the domain's DNS area, look for the DNSSEC option. Add the DS data exactly as it was displayed by the Cloudflare. Check each field before saving, especially the digest.

    If the Registro.br already has an old DS registered, remove or replace it with the Cloudflare's current DS. Don't leave old DS pointing to another DNS provider.

  6. 06

    Wait for propagation and validate

    After saving, wait for the change to be published and validate that the domain has a DS record and that the DNSSEC chain is working.

How to validate DNSSEC

After configuring the DS, validate in more than one tool. With terminal, you can start by:

View published DS record

dig DS exemplo.com.br +short

Test DNSSEC validation

dig exemplo.com.br +dnssec

Another useful validation is to use DNSViz, which visually shows whether the DNSSEC string is valid or where there is an error.

Common mistakes when configuring DNSSEC

  • Add DS before Cloudflare is active: confirm nameservers and zone before enabling DNSSEC.
  • Keep old DS: Another provider's DS may break DNSSEC validation.
  • Copy Incomplete Digest: check whether the long value was copied in its entirety.
  • Confusing DNSSEC with SSL: DNSSEC protects DNS resolution; SSL/TLS secures the HTTPS connection.

FAQ

DNSSEC changes my nameservers?

No. DNSSEC does not change nameservers. It adds a cryptographic signature to DNS resolution. Nameservers must be correct before configuration.

What is the DS register used in Registro.br?

DS stands for Delegation Signer. It is published to the registrar to point to the DNSSEC key of the zone hosted on Cloudflare and close the chain of trust.

Can I copy a sample DS?

No. Each domain has its own DNSSEC data. Use only the values ​​generated by Cloudflare for the domain you are configuring.

Can the domain stop resolving if DNSSEC is wrong?

Yes. An incorrect or old DS can cause DNSSEC validation failure on resolvers that validate DNSSEC. Therefore, check the data before saving.

Conclusion

To configure DNSSEC on the Registro.br using Cloudflare, enable DNSSEC on the Cloudflare, copy the data from the DS record, and publish this data to the Registro.br. The most important point is to ensure that the published DS exactly matches the current key of Cloudflare.

After saving, validate with digor DNSViz and monitor the Cloudflare panel until the status is healthy.

BedHosting LTDA | CNPJ: 60.677.890/0001-00 | BedHosting.com.br