What is DNSSEC?
In theory, a DNS without DNSSEC can be manipulated through so-called cache poisoning or man-in-the-middle attacks. By activating DNSSEC you make sure that this at least cannot happen to your domain.
This extension to the DNS protocol therefore makes using DNS and domain names a lot more secure.
To prevent these types of attacks, DNSSEC links the answer to a DNS query to a digital signature. This makes it possible to check whether the information a DNS server sends really comes from the right DNS server. To achieve this, the DNS servers are equipped with a system of asymmetric cryptography, also known as public-key cryptography. The DNS information is signed with a private key, just as when a website is secured with a certificate. Users with a public key can then verify that the information sent is correct and that there are no problems with it.
Click here for an explanation of how to activate DNSSEC
