Sign your DNS zone with DNSSEC
dnssec-unsigned
Unsigned DNS answers cannot be verified, so a resolver on the path can hand clients the wrong address for your domain. Sign the zone.
Why this matters
DNS isn't DNSSEC-signed. DNS responses can't be cryptographically verified, but most sites don't use DNSSEC yet.
CDN and edge
Cloudflare
- 1 Go to DNS > Settings
- 2 Click Enable DNSSEC
- 3 Add the DS record shown to your domain registrar
Does your app still have this?
Scan your domain