# Step 16 — DNSSEC or it doesn’t count

DNS-AID records are only trustworthy when signed. Enable DNSSEC at your DNS provider, then publish the DS record at the registrar — key tag, algorithm 13, digest type 2. Until the parent zone carries the DS, resolvers answer AD: false and the check stays red.

Canonical: https://robauto.ai/learn/advanced-agentic-commerce/18

_Advanced Agentic Commerce: Ship the Full Agent Surface — lesson 18 of 20 (PLAYBOOK)_

DNS-AID records are only trustworthy when signed. Enable DNSSEC at your DNS provider, then publish the DS record at the registrar — key tag, algorithm 13, digest type 2. Until the parent zone carries the DS, resolvers answer AD: false and the check stays red.

Source: [IETF RFC 9364 (DNSSEC)](https://www.rfc-editor.org/rfc/rfc9364.html?utm_source=robauto)

[Previous lesson](/learn/advanced-agentic-commerce/17) · [Next lesson](/learn/advanced-agentic-commerce/19) · [Course overview](/learn/advanced-agentic-commerce) · [All courses](/learn)

---

(c) 2026 Robauto, Inc. — support@robauto.ai
Machine surfaces: https://robauto.ai/llms.txt · https://robauto.ai/llms-full.txt · https://robauto.ai/.well-known/api-catalog
