Home
Lookup Tools
Analysis
Bulk & Enterprise
Resources
Close

CDNSKEY Record DNSSEC

The CDNSKEY record (Child DNSKEY) works alongside CDS records to enable automated DNSSEC key management. It publishes the child zone's DNSKEY in a format the parent can use to automatically compute and update DS records.

Look Up CDNSKEY Records

Check CDNSKEY records for any domain using our free DNS lookup tool.

Look Up CDNSKEY Records →

What Is a CDNSKEY Record?

While CDS contains the hash (digest) of the key, CDNSKEY contains the actual public key. The parent zone can then compute the DS record directly from the CDNSKEY.

Publishing both CDS and CDNSKEY provides maximum compatibility with different registry systems.

CDNSKEY Record Format

Example CDNSKEY Record

example.com.    3600    IN    CDNSKEY    257 3 13 mdsswUyr3DPW...base64key...

Same format as DNSKEY: flags, protocol, algorithm, public key.

CDNSKEY vs CDS

Aspect CDNSKEY CDS
Contains Full public key Key hash (digest)
Parent computes DS Yes (from key) No (DS provided)
Size Larger Smaller
Flexibility Parent chooses digest Child specifies digest

How CDNSKEY Works

  1. Child publishes CDNSKEY with desired KSK
  2. Parent retrieves and validates CDNSKEY
  3. Parent computes DS hash from CDNSKEY
  4. Parent publishes DS record

DNSSEC Removal with CDNSKEY

Special CDNSKEY to request DNSSEC removal (RFC 8078):

example.com.    CDNSKEY    0 3 0 AA==

This signals the parent to remove all DS records.

CDNSKEY Best Practices

Registry Support

CDNSKEY support varies by registry. Some prefer CDS, others prefer CDNSKEY, and many support both. Check with your registry/registrar for specific requirements.

Troubleshooting CDNSKEY

Common issues and solutions:

Check Your CDNSKEY Records

Use our DNS Record Finder to look up CDNSKEY records for any domain.

Look Up CDNSKEY Records →

Related Record Types