DNSSEC

Every zone CNX serves is signed with DNSSEC automatically — there's no opt-in step. When a zone is provisioned, CNX generates a Key Signing Key (KSK) inside its HSM-backed key-management system, along with a Zone Signing Key (ZSK) used day to day to sign the zone's records. The KSK in turn signs the ZSK, and a DS (Delegation Signer) record derived from the KSK is what your parent zone (e.g. .com) publishes to link your zone into the chain of trust.

Only the KSK's DS record needs anything from you. ZSK rollovers happen entirely inside CNX's platform on a regular schedule and require no customer action at all. The KSK is different: because its DS record lives at your registrar, outside CNX's control, publishing or updating it is always a step you have to take yourself — see Publishing and updating DS records.

KSK rollover happens at your request. Where your subscription includes the compliance evidence package, the daily reports carry the current KSK's attestation and DS records under latest/, so you always have a source of truth for what should be published at your registrar.