To maintain a high level of security within DNSSEC, we are phasing out several older and vulnerable algorithms and digest types.
This change is effective on 28 January 2026, and affects the DNSSEC configuration for the .dk domain names you currently manage as Nameserver Manager.
What This Means
On the date above, we will remove DS Resource Records (DS RR) from the Whois database that utilizes one or more of the following security types:
Algorithms: 5 (RSA/SHA-1), 7 (RSASHA1-NSEC3-SHA1), and 10 (RSASHA512)
Digest Type: 1 (SHA-1)
Action Required
To ensure uninterrupted DNSSEC protection for the domains under your management, we strongly recommend that you add new, supported DNSSEC algorithms to all affected .dk domain names before 28 January 2026.
Failure to update these records before the deadline will result in the domains temporarily losing their DNSSEC validation.
Thank you for your cooperation in ensuring the continued security of the .dk zone.
Please don't hesitate to reach out if you have any questions.