createkeys.pl addpublickeytozone.pl signzone.pl edit zone stanza to reflect file $domain.signed rndc reload $domain check locally: dig DNSKEY $domain @localhost +multiline dig A $domain @localhost +noadditional +dnssec +multiline cat dsset-$domain. go to $registrar and add Delegation Signer Record check for DS record globally dig +trace +noadditional DS $domain @8.8.8.8 | grep DS