DNSSEC stands for Domain Name System Security Extensions. It is used to secure information provided by the DNS as valid and uncompromised. It is a layer of security to protect the process of exchanging information during DNS lookup procedure that has become an integral part in accessing website through the internet.

DNSSEC is achieved with the implementation of using keys and signatures. DNSKEY is used for verification and it is published in the DNS as public key. The private key however is used for signing and is never published. Please refer to the DNSSEC diagram to get a better understanding on how DNSSEC works.

DNSSEC Exchange Flow