As organizations adopt multi-cloud and multi-provider DNS strategies, multi-signer DNSSEC has become an important capability for maintaining both resilience and security. With our latest enhancement, multi-signer DNSSEC easier to use by enhancing the API to provide authoritative information about zsigning keys (ZSKs).
managed by NS1 Connect are now available via the NS1 Connect Restful API, bringing greater clarity, safety and automation to DNSSEC operations.
In a multi-signer DNSSEC setup, multiple providers sign the same zone concurrently. This allows operators to:
Until now, customers using NS1 Connect as a signer faced a limitation as KSKs were available via API, ZSKs were not. This resulted in customers inferring ZSKs via DNS lookups. While workable, this approach introduced ambiguity and operational risk, especially in automated, multi-provider environments where precision is critical.
What is Changing in NS1 Connect
We are enhancing the authoritative Connect API to explicitly expose Connect created ZSKs associated with a signed zone.
Authoritative API access to ZSKs managed by NS1 Connect - ZSKs are returned directly from the NS1 Connect signer, rather than inferred from DNS. Keys are explicitly marked as Connect created and the key role is clearly defined (ZSK vs KSK).
Most importantly, this data comes from a single authoritative source – the Connect signer itself.
Multi-signer DNSSEC was designed to enable secure DNS across multiple providers, a foundational requirement for modern, resilient architectures. This enhancement strengthens that model with:
Sfor safe, automated multi-signer workflows – eliminating DNS inference and providing authoritative ZSK data.
Clear ownership, no ambiguity – preventing any accidental mixing of key ownership, reducing the risk of misconfiguration.
DNSSEC adds a critical layer of trust to the internet by ensuring DNS responses are authentic and untampered. Multi-signer DNSSEC extends that trust across providers but only if the underlying key management is reliable.
By making ZSK access explicit, authoritative and automation-friendly, this enhancement removes a key barrier to adoption and helps customers confidently operate DNSSEC in multi-provider environments.