Cloudflare Security & compliance Releases

DNSSEC not active on the zone

Part of the Edge TLS posture check · fix arrives as a guide

What it is

DNSSEC is not active on the zone.

Why it matters

Without it, DNS responses for your domain are unsigned, so a resolver has no way to detect a forged answer. Cache poisoning sends your users to someone else's server with your domain in the address bar.

How to fix it

Enable DNSSEC in the Cloudflare dashboard, then add the DS record it produces at your registrar. It is inactive until that record is published, so both steps are required.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.