---
title: DNSSEC Details
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api)

[DNS](https://developers.cloudflare.com/api/resources/dns)

[DNSSEC](https://developers.cloudflare.com/api/resources/dns/subresources/dnssec)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# DNSSEC Details

GET/zones/{zone\_id}/dnssec

Details about DNSSEC status and configuration.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`DNS Read``DNS Write`

##### P ath ParametersExpand Collapse

zone\_id: string

Identifier.

maxLength32

[Link to this property](<#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(params)%20default%20%3E%20(param)%20zone_id%20%3E%20(schema)>)

##### ReturnsExpand Collapse

<details>

<summary>

errors: array of object {code, message, documentation\_url, source }

</summary>

code: number

minimum1000

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20code">Link to this property</a>

message: string

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

documentation\_url: optional string

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20documentation_url">Link to this property</a>

<details>

<summary>

source: optional object {pointer }

</summary>

pointer: optional string

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20pointer">Link to this property</a>

</details>

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

[Link to this property](<#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20errors>)

<details>

<summary>

messages: array of object {code, message, documentation\_url, source }

</summary>

code: number

minimum1000

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20code">Link to this property</a>

message: string

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

documentation\_url: optional string

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20documentation_url">Link to this property</a>

<details>

<summary>

source: optional object {pointer }

</summary>

pointer: optional string

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20pointer">Link to this property</a>

</details>

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

[Link to this property](<#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20messages>)

success: true

Whether the API call was successful.

[Link to this property](<#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20success>)

<details>

<summary>

result: optional <a href="https://developers.cloudflare.com/api/resources/dns#(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)">DNSSEC</a> { algorithm, digest, digest\_algorithm, 11 more }

</summary>

algorithm: optional string

Algorithm key code.

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20algorithm">Link to this property</a>

digest: optional string

Digest hash.

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20digest">Link to this property</a>

digest\_algorithm: optional string

Type of digest algorithm.

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20digest_algorithm">Link to this property</a>

digest\_type: optional string

Coded type for digest algorithm.

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20digest_type">Link to this property</a>

dnssec\_multi\_signer: optional boolean

If true, multi-signer DNSSEC is enabled on the zone, allowing multiple providers to serve a DNSSEC-signed zone at the same time. This is required for DNSKEY records (except those automatically generated by Cloudflare) to be added to the zone.

See <a href="https://developers.cloudflare.com/dns/dnssec/multi-signer-dnssec/">Multi-signer DNSSEC</a> for details.

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20dnssec_multi_signer">Link to this property</a>

dnssec\_presigned: optional boolean

If true, allows Cloudflare to transfer in a DNSSEC-signed zone including signatures from an external provider, without requiring Cloudflare to sign any records on the fly.

Note that this feature has some limitations. See <a href="https://developers.cloudflare.com/dns/zone-setups/zone-transfers/cloudflare-as-secondary/setup/#dnssec">Cloudflare as Secondary</a> for details.

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20dnssec_presigned">Link to this property</a>

dnssec\_use\_nsec3: optional boolean

If true, enables the use of NSEC3 together with DNSSEC on the zone. Combined with setting dnssec\_presigned to true, this enables the use of NSEC3 records when transferring in from an external provider. If dnssec\_presigned is instead set to false (default), NSEC3 records will be generated and signed at request time.

See <a href="https://developers.cloudflare.com/dns/dnssec/enable-nsec3/">DNSSEC with NSEC3</a> for details.

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20dnssec_use_nsec3">Link to this property</a>

ds: optional string

Full DS record.

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20ds">Link to this property</a>

flags: optional number

Flag for DNSSEC record.

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20flags">Link to this property</a>

key\_tag: optional number

Code for key tag.

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20key_tag">Link to this property</a>

key\_type: optional string

Algorithm key type.

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20key_type">Link to this property</a>

modified\_on: optional string

When DNSSEC was last modified.

formatdate-time

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20modified_on">Link to this property</a>

public\_key: optional string

Public key for DS record.

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20public_key">Link to this property</a>

<details>

<summary>

status: optional "active"or "pending"or "disabled"or 2 more

Status of DNSSEC, based on user-desired state and presence of necessary records.

</summary>

One of the following:

"active"

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"pending"

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"disabled"

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"pending-disabled"

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

"error"

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20dns.dnssec%20%3E%20(model)%20dnssec%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

</details>

[Link to this property](<#(resource)%20dns.dnssec%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result>)

### DNSSEC Details

HTTP

HTTPTypeScriptPythonGoTerraform

```
curl https://api.cloudflare.com/client/v4/zones/$ZONE_ID/dnssec \
    -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "algorithm": "13",
    "digest": "48E939042E82C22542CB377B580DFDC52A361CEFDC72E7F9107E2B6BD9306A45",
    "digest_algorithm": "SHA256",
    "digest_type": "2",
    "dnssec_multi_signer": false,
    "dnssec_presigned": true,
    "dnssec_use_nsec3": false,
    "ds": "example.com. 3600 IN DS 16953 13 2 48E939042E82C22542CB377B580DFDC52A361CEFDC72E7F9107E2B6BD9306A45",
    "flags": 257,
    "key_tag": 42,
    "key_type": "ECDSAP256SHA256",
    "modified_on": "2014-01-01T05:20:00Z",
    "public_key": "oXiGYrSTO+LSCJ3mohc8EP+CzF9KxBj8/ydXJ22pKuZP3VAC3/Md/k7xZfz470CoRyZJ6gV6vml07IC3d8xqhA==",
    "status": "active"
  }
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "algorithm": "13",
    "digest": "48E939042E82C22542CB377B580DFDC52A361CEFDC72E7F9107E2B6BD9306A45",
    "digest_algorithm": "SHA256",
    "digest_type": "2",
    "dnssec_multi_signer": false,
    "dnssec_presigned": true,
    "dnssec_use_nsec3": false,
    "ds": "example.com. 3600 IN DS 16953 13 2 48E939042E82C22542CB377B580DFDC52A361CEFDC72E7F9107E2B6BD9306A45",
    "flags": 257,
    "key_tag": 42,
    "key_type": "ECDSAP256SHA256",
    "modified_on": "2014-01-01T05:20:00Z",
    "public_key": "oXiGYrSTO+LSCJ3mohc8EP+CzF9KxBj8/ydXJ22pKuZP3VAC3/Md/k7xZfz470CoRyZJ6gV6vml07IC3d8xqhA==",
    "status": "active"
  }
}
```