Please confirm a few concerns prior to implementing DNSSEC

Hello, my team is looking to implement DNSSEC and was hoping the community could quell two concerns the team has been asking about and I haven’t been able to answer.

  1. Once I enable DNSSEC in Cloudflare and create the DX records it may take some time for our domain registrar to update the records on their end (or so I am told). During this time we wanted to ensure that the zone is still available and traffic would not be disrupted. Based on what I’ve read, during this time the DNSSEC status would just show as “pending” and otherwise the zone would not be impacted or otherwise unavailable, right?

  2. So long as I continue to use Cloudflare for authoritative DNS, DNSSEC won’t interfere with creating new DNS records or modifying existing ones. We have some A-records that get changed during a release window then changed back when the maintenance is completed, I wanted to confirm the team can continue doing that without issues.

Thank you for any feedback, I just want to ensure that I’m not causing any disruption while trying to get DNSSEC implemented.

Why Wait
Don’t wait for an answer, find it fast! Search for #CommunityTip error:
Example: #CommunityTip 521

Yes and Yes. Enabling DNSSEC will not interfere in any way, unless you make a mistake in adding the DS record to your registrar.

1 Like

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.