Review Cloud DNS DNSSEC configuration

Configure public-zone signing together with the parent DS records.

Description

DNSSEC for a public Cloud DNS zone helps validate the origin and integrity of DNS responses. It requires zone signing, correct DS records in the parent zone and a validating resolver. It does not encrypt DNS data.

Cloud DNS DNSSEC settings apply to public zones. The same configuration should not be applied indiscriminately to private zones.

Potential impact

  • Trusting forged responses can direct users to unintended addresses.
  • Inconsistent signing state and DS records can interrupt legitimate name resolution.

Remediation

  • Set dnssecConfig.state: "on" for the public zone and register the correct DS records with the registrar or parent zone.
  • Follow the documented DS-record and TTL procedures for key changes or disabling DNSSEC, and test resolution with a validating resolver.

Examples

These excerpts show public-zone settings in the retired Deployment Manager format. Supply the actual domain and omitted required settings through a supported tool, and configure delegation and DS records separately.

Before

yaml
resources:
  - name: dns
    type: dns.v1.managedZone
    properties:
      name: my-zone

After

yaml
resources:
  - name: dns
    type: dns.v1.managedZone
    properties:
      name: my-zone
      dnssecConfig:
        state: "on"

Explanation:

  • Before: The zone's DNSSEC settings are omitted. Check its effective signing state and parent delegation.
  • After: Zone signing is enabled. The parent chain of trust and client validation are also needed for protection.

References