Review GCP Cloud DNS DNSSEC configuration

Configure public-zone signing and parent DS records together.

Description

Without DNSSEC, a public DNS zone cannot provide signature-based verification of DNS data origin and integrity. Trusting a forged response can direct users to an unintended address.

DNSSEC does not encrypt DNS data. Zone signing, correct DS records in the parent zone and a validating resolver are all required.

Potential impact

  • Forged DNS responses can direct users to impersonated services.
  • A mismatch between signing state and DS records can interrupt legitimate name resolution.

Remediation

  • Set dnssec_config.state = "on" for the public zone and register the correct DS records with its registrar or parent zone.
  • Follow official DS-record and TTL transition procedures for key changes or disabling DNSSEC, and test resolution with a validating resolver.

Examples

These examples compare public managed zones. Replace the name and domain with actual values, and configure parent delegation and DS records separately. Do not apply these settings unchanged to private zones.

Before

hcl
resource "google_dns_managed_zone" "example" {
  name     = "foobar"
  dns_name = "foo.bar."

  dnssec_config {
    state         = "off"
    non_existence = "nsec3"
  }
}

After

hcl
resource "google_dns_managed_zone" "example" {
  name     = "foobar"
  dns_name = "foo.bar."

  dnssec_config {
    state         = "on"
    non_existence = "nsec3"
  }
}

Explanation:

  • Before: DNSSEC signing is disabled for the zone.
  • After: DNSSEC signing is enabled. The parent trust chain and a validating resolver are also needed for protection.

References