DNSSEC Protection Disabled

Low Severity Technical Guide

Vulnerability Description

DNS Security Extensions (DNSSEC) adds cryptographic signatures to your DNS records. Without DNSSEC, the DNS resolution process is vulnerable to spoofing and cache poisoning attacks, where an attacker redirects your users to a clone of your site by injecting a spoofed IP address.

Remediation Guide

To resolve this vulnerability, follow these config changes or developer practices:

Enable DNSSEC at your domain registrar (e.g. GoDaddy, Namecheap, Route 53) and upload the DS (Delegation Signer) records provided by your DNS host to authenticate your zones cryptographically.

Verify Your Fix

After applying the remediation, run an external attack-surface scan to verify that the vulnerability is no longer detected by WebScanify.

Is your website vulnerable?

Run a free security scan now to identify missing headers, outdated JS, and other deployment vulnerabilities.