Upsert DNSSEC configuration
PUT /dns/{domain}/dnssecOperation ID: PutDNSSECByDomain
Enable, disable, or update registry DNSSEC for the specified domain.
Use mode=regfish only when the domain uses regfish authoritative nameservers.
Use mode=external only when DNSSEC data must be supplied for external nameservers.
Use mode=none together with state=disabled to disable registry DNSSEC.
The response may already be final, or it may include a pending_job while
the registry or DNS delegation is still converging.
If the update cannot be completed, the response returns the last stable DNSSEC state.
Path parameters
Section titled “Path parameters”| Name | Type | Required | Description |
|---|---|---|---|
domain |
fqdn_relaxed | yes | — |
Request body
Section titled “Request body”| Field | Type | Required | Description |
|---|---|---|---|
mode |
dnssecMode | yes | Requested DNSSEC operating mode. - none: no registry DNSSEC should remain active - regfish: regfish signs the zone and manages registry trust anchors - external: the caller supplies DNSSEC records for external authoritative nameservers (none, regfish, external) |
state |
string |
yes | Desired high-level DNSSEC state. (disabled, enabled) |
verify_after_apply |
boolean |
no | When true, the API immediately refreshes registry state and checks DNS delegation after the update. |
records |
dnssecRecord[] | no | Required for mode=external,state=enabled. Ignored for regfish-managed activation and for disable operations. |
Responses
Section titled “Responses”| Status | Type | Description |
|---|---|---|
200 |
dnssecResponse |
DNSSEC configuration accepted |
400 |
Error |
Invalid DNSSEC payload |
401 |
Error |
Unauthorized |
404 |
Error |
Domain not found |
409 |
Error |
DNSSEC cannot be applied in the requested mode or provider state |
417 |
Error |
DNSSEC record set is invalid for this TLD or provider |
502 |
Error |
Registry-side DNSSEC operation failed |
Response body
Section titled “Response body”| Field | Type | Required | Description |
|---|---|---|---|
success |
boolean |
yes | Success indicator |
code |
integer |
no | Response/Error Code |
response |
dnssecResponse | no | — |
Example
Section titled “Example”curl -X PUT "https://api.regfish.com/dns/<domain>/dnssec" \ -H "x-api-key: $REGFISH_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "mode": "none", "state": "disabled", "verify_after_apply": true, "records": [ { "kind": "ds", "key_tag": 0, "flags": 0, "protocol": 0, "algorithm": 0, "digest_type": 0, "digest": "string", "public_key": "string", "comment": "string" } ] }'Build a request
Section titled “Build a request”Fill in values — the call below updates as you type. Nothing is sent: the API does not currently allow browser requests from this domain (CORS). The API key is not stored.