DNS hostingDNS hostingCapabilities verified
deSEC
Migrate DNS zones to or from deSEC: what's supported, what access you need, and what changes for each destination.
See how a domain's records would land at deSEC. Free and read-only.
Access we need
- Credentials
- API token
- Permissions
- Any token can read all RRsets. Applying needs write permission on the RRsets (token policies can restrict it); creating zones needs perm_create_domain.
What deSEC supports
The same data the translation engine uses when it plans a migration.
- Create zones through the API
- List zones through the API
- Turn on DNSSEC through the API
- Apex CNAME (flattening)
- Apex ALIAS record
- Aliases to cloud resources
- CDN proxy on records
- Routing policies
- Minimum TTL
- 3600s
Record types
- A
- AAAA
- CNAME
- MX
- TXT
- NS
- SRV
- CAA
- PTR
- DS
- HTTPS
- SVCB
- TLSA
- SSHFP
- NAPTR
- SPF
- LOC
- CERT
- URI
- DHCID
- DNAME
- OPENPGPKEY
- RP
- SMIMEA
Good to know
- The minimum TTL is 3600 seconds for most domains (deSEC sets it per domain) and the maximum is 86400.
- ALIAS/ANAME records and apex CNAMEs aren't supported; use A/AAAA or HTTPS records at the apex.
- Every zone is DNSSEC-signed automatically. Give the DS records to your registrar to complete the chain.