Skip to content
DNS hostingDNS hostingCapabilities verified

deSEC

Migrate DNS zones to or from deSEC: what's supported, what access you need, and what changes for each destination.

See how a domain's records would land at deSEC. Free and read-only.

Access we need

Credentials
API token
Permissions
Any token can read all RRsets. Applying needs write permission on the RRsets (token policies can restrict it); creating zones needs perm_create_domain.
deSEC API documentation

What deSEC supports

The same data the translation engine uses when it plans a migration.

Create zones through the API
List zones through the API
Turn on DNSSEC through the API
Apex CNAME (flattening)
Apex ALIAS record
Aliases to cloud resources
CDN proxy on records
Routing policies
Minimum TTL
3600s

Record types

  • A
  • AAAA
  • CNAME
  • MX
  • TXT
  • NS
  • SRV
  • CAA
  • PTR
  • DS
  • HTTPS
  • SVCB
  • TLSA
  • SSHFP
  • NAPTR
  • SPF
  • LOC
  • CERT
  • URI
  • DHCID
  • DNAME
  • OPENPGPKEY
  • RP
  • SMIMEA

Good to know

  • The minimum TTL is 3600 seconds for most domains (deSEC sets it per domain) and the maximum is 86400.
  • ALIAS/ANAME records and apex CNAMEs aren't supported; use A/AAAA or HTTPS records at the apex.
  • Every zone is DNSSEC-signed automatically. Give the DS records to your registrar to complete the chain.