2. Namecheap: DNSSEC DS Record
Status: ⏳ Needs action
What: Cloudflare generated the DNSSEC keys and is waiting for the DS record to be added at the registrar (Namecheap) to complete the chain of trust.
Why: DNSSEC protects against DNS spoofing/cache poisoning by cryptographically signing DNS records. Without the DS record at the registrar, the chain is incomplete.
How (30 seconds): 1. Log into namecheap.com 2. Domain List → relik.africa → Advanced DNS → DNSSEC tab 3. Add this DS record:
| Field | Value |
|---|---|
| Key Tag | 2371 |
| Algorithm | 13 (ECDSAP256SHA256) |
| Digest Type | 2 (SHA-256) |
| Digest | 71B3EAD46F0CFA6E80CEDB73C6C9D6403BD4EB73A523F34B50EFB6DB6A0E7A5B |
Propagation: 1–24 hours.