Cloudflare
Security & compliance
Releases
DNSSEC not active on the zone
Part of the Edge TLS posture check · fix arrives as a guide
What it is
DNSSEC is not active on the zone.
Why it matters
Without it, DNS responses for your domain are unsigned, so a resolver has no way to detect a forged answer. Cache poisoning sends your users to someone else's server with your domain in the address bar.
How to fix it
Enable DNSSEC in the Cloudflare dashboard, then add the DS record it produces at your registrar. It is inactive until that record is published, so both steps are required.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.