The Secure Way
DNS and DNSSEC, the secure way
Signed zones, key rollovers that do not take your domain down, hidden primaries and zone transfers.
14 guides
- Building your own GeoIP CDN, the secure wayBuild a GeoIP CDN with a hidden DNSSEC signer and Knot edges that hold only the ZSK: signed geo answers, daily re-signing, and PoP failover in one edit.
- CAA records bound to your ACME account, the secure wayLimit who can get certificates for your domain: CAA with accounturi and validationmethods, no wildcards by default, DNSSEC-signed, and a per-subdomain override.
- DNS rate limiting and cookies in Knot, the secure wayStop Knot DNS from acting as a reflection amplifier: mod-rrl with slip, mod-cookies loaded first so real clients pass, and one cookie secret across anycast.
- DS records and delegation at the registrar, the secure wayThe DS record is the one DNSSEC step you cannot do on your own server. Get it right at the registrar, check it from the parent, and remove it before you unsign.
- Emergency DNSSEC key revocation, the secure wayWhat to do in Knot DNS when a ZSK or KSK leaks: swap the ZSK in minutes, replace the KSK in the right order with the registrar, and why panic deletion fails.
- GeoDNS with Knot and DNSSEC, the secure wayServe location-based answers from Knot DNS mod-geoip with valid DNSSEC signatures: manual keys, a reload after each ZSK change, and a test from every region.
- Knot DNS automatic DNSSEC signing, the secure wayTurn on DNSSEC in Knot DNS 3.5 with automatic keys, NSEC3 set per RFC 9276, a guarded KASP database and a validated chain, plus the DS step Knot waits on.
- Knot DNSSEC key rollover, the secure wayRoll ZSKs and KSKs in Knot DNS without going bogus: lifetimes, TTL timing, a parent DS check, the registrar step, and the timeout that quietly breaks the chain.
- Monitoring DNSSEC signature expiry, the secure wayCatch expiring RRSIGs before resolvers do: check every authoritative server directly, set thresholds from your refresh window, and size SOA expire to match.
- Offline KSK with Knot, the secure wayKeep the DNSSEC KSK off your Knot DNS servers: the KSR and SKR ceremony, keytag split, an air-gapped signer, and the SKR expiry that turns a zone bogus.
- PowerDNS hidden primary with Knot secondaries, the secure wayRun PowerDNS as a hidden, signing primary behind Knot DNS secondaries: a private transfer network, TSIG on every transfer, SOA-EDIT, and validation on the edge.
- Split-horizon DNS for private services with CoreDNS, the secure wayGive internal clients private answers and everyone else public ones with the CoreDNS view plugin, without leaking private names or shadowing the internal view.
- TSIG for zone transfers and key rotation, the secure wayProtect AXFR, IXFR and NOTIFY with TSIG in Knot DNS: hmac-sha256, address plus key ACLs, versioned key names, and a key rotation with no failed transfers.
- Zone files in git, reconciled to PowerDNS, the secure wayKeep DNS zones in git and make PowerDNS match them: validate before apply, detect drift from API edits, keep serials moving forward, and lock the API down.
T Academy
Every guide here is taught hands-on in H2-CPQE Edge and Post-Quantum Networking: a real host in your browser, and every objective checked on the machine.
Start free