Independent comparison · no paid rankings
Home / Blog / Technical / Hostpoint and DNSSEC: sign a zone without complicating domain changes

Hostpoint and DNSSEC: sign a zone without complicating domain changes

DNSSEC at Hostpoint secures DNS resolution, but poorly managed keys or forgotten TTLs complicate migrations and domain transfers.

Hébergeurs.eu Editorial Team 4 min read Updated Jul 19, 2026

A cantonal bank enables DNSSEC on its .ch domain via Hostpoint. Migration to a new registrar starts without removing the DS record: for forty-eight hours, some resolvers see SERVFAIL — not phishing, not an attack, just an ignored DNSSEC procedure. The network team then discovers DNSSEC is not a switch you flip once, but a chain of trust linking registrar, DNS zone, and every future change.

Hostpoint combines Swiss hosting and DNS management — DNSSEC strengthens response integrity and protects against spoofing. It requires discipline on DS records, TTLs, and operation order during changes. Without a written procedure, signing becomes an operational risk as much as a security asset.

Enable DNSSEC cleanly at Hostpoint

Activation follows a precise sequence. First, sign the zone in the Hostpoint panel (or via API if your plan allows). Then copy the DS values (or DNSKEY) displayed by Hostpoint. Publish one coherent set at the registrar — never two contradictory DS records. Wait for propagation (TTL plus registrar delay), then validate with dig +dnssec on your A, AAAA, and MX records.

StepRisk if skipped
DS published without signed zoneSERVFAIL for all validators
Contradictory double DSIntermittent failures depending on resolvers
TTL at 86400 before a changeSlow migration, difficult rollback
Forgotten KSK rotationSignature expiry, DNS outage

Each step links Hostpoint (zone signing) to the registrar (DS publication). One without the other breaks the chain.

Domain changes without breakage

Adding a subdomain is generally transparent if the zone is already signed automatically. However, a nameserver change to another DNS provider requires a strict sequence: lower TTL several days before, remove DS at the registrar (or disable DNSSEC), migrate the zone, re-sign at the new DNS, then republish DS.

For a .ch registrar transfer, coordinate SWITCH, the registrar, and Hostpoint if DNS stays with Hostpoint during transfer. Document a written procedure — marketing or sales teams must never modify DS records alone.

Most common errors: leaving DS active after an unsigned zone, mixing Hostpoint DNS and Cloudflare without re-signing, forgetting RRSIG expiry monitoring, or ignoring CNAME flattening and DNSSEC compatibility depending on the offer.

If domain-related data falls under Swiss GDPR rules, cross-read our guide Swiss host and data transfers.

Monitor and rotate keys

DNSSEC relies on two key types. ZSK (Zone Signing Key) signs daily records; KSK (Key Signing Key) signs the ZSK. Hostpoint may automate ZSK rotation if the panel manages it. KSK rotation, rarer but critical, requires registrar DS update — schedule it outside migration periods.

Set up RRSIG expiry alerts: an expired signature has the same effect as desynchronised DS. Test dig +dnssec after every DS change, and keep a history of previous DS values for quick rollback.

The climax: DNS security that punishes sloppy migrations

Decide and move forward without blind spots

Start by writing a DNSSEC procedure shared between technical and legal teams, with registrar and Hostpoint contacts. Set up RRSIG expiry monitoring from activation. Before any nameserver or registrar change, lower TTL to 300 seconds at least forty-eight hours ahead. After every DS modification, validate with dig +dnssec from several public resolvers. See the Hostpoint profile and our guides if your project goes beyond a simple brochure site.

Frequently asked questions

Does Hostpoint offer DNSSEC?

Hostpoint enables DNSSEC on zones it hosts, publishing DNSKEY records and signatures. Check in the panel that your plan combines domain and Hostpoint DNS — signing only works when the zone is hosted with them.

Where to publish the DS record?

At the domain registrar (.ch, .com, etc.) via DS or DNSKEY records depending on the interface. Hostpoint displays values to copy; any mismatch between published DS and signed zone causes SERVFAIL for DNSSEC-validating resolvers.

Does DNSSEC complicate transfer?

Yes, if the procedure is neglected. Disable DNSSEC at the registrar before migration, transfer the zone, re-sign at the new DNS, then republish DS. Without this order, strict validators fail with incorrectly signed NSEC or NXDOMAIN responses.

Key rotation frequency?

ZSK rotation can be automated if the panel manages it. KSK rotation requires planning with registrar DS update — document schedule, owners, and rollback procedure before any operation.


Enable DNSSEC with a written migration procedure — signing without discipline is a double-edged sword.

See the Hostpoint sheet

Independent scores, plans, pros/cons and alternatives to Hostpoint.

Open the Hostpoint sheet
Blog

Related reading

All articles →