Skip to content

Enable or disable DNSSEC

Use the Enhance main control panel server with a valid cPFence license and a Super admin API key. WebUI users need access to the selected websites and permission for this action.

  1. Open Tools & Utilities → ApiMachine Bulk Tools.
  2. Choose Cluster scope or Select servers, apply your filters, then check the intended website rows. Review the selection rules; filtering alone does not select websites.
  3. Open Choose action → DNS & Email → Enable DNSSEC or Disable DNSSEC.

DNS and Email action menu showing Enable DNSSEC and Disable DNSSEC.

Choose the intended DNSSEC action. Remove upstream DS records before disabling signing. Select the image to enlarge it; use your browser's Back command to return.
  1. Review the selected websites and Confirm and run. Read Finished or Needs attention and the per-target output.

When enabling, copy the returned DS records to the upstream DNS provider or registrar as required. Keep the records synchronized with Enhance.

Check per-domain results, DS records, and DNS resolution. Missing or mismatched records require attention before treating the setup as complete.

Use root on the main control panel server. Generate and edit the CLI site list first so that /var/log/cpfenceav/cluster-sites-list.txt contains only your intended targets.

Action Command
Enable DNSSEC cpfence --bulk-enable-dnssec-cluster
Disable DNSSEC after upstream DS removal cpfence --bulk-disable-dnssec-cluster

Run the command for your intended choice and confirm its target list.

For failures, read each target’s error and check its actual state before retrying. Keep the retry selection limited to the intended websites.