DNSSEC Statistics
of ccTLDs in Africa

Welcome to our page, where we provide detailed insights into the DNSSEC signing status of the 54 two-letter country code top-level domains (ccTLDs) assigned to Africa.

For each signed ccTLD, you'll find key information, including the DNSSEC signing algorithm currently in use, the tag (ID) of each Key Signing Key (KSK) in the ccTLD zone, and the date a Delegation Signer (DS) record was first observed in the root zone, along with more details.

You can also use filters to focus on specific sub-regions, signing statuses, or other criteria based on your interests. Additionally, we offer graphs that give a clear overview of global DNSSEC trends for added context.

Failed to load DNSSEC data. Please try again later.

Keywords:

DS: Delegation Signer

DNSKEY: A resource record in any DNSSEC signed zone. It is where the public part of the ZSK and KSK are published.

No DNSSEC: ccTLD has not signed their zone file, no DNSKEY present in the zone, and No DS in root zone.

DNSSEC Signed - Not active: ccTLD is DNSSEC signed with DNSKEY present in the zone but No DS present in root zone.

DNSSEC Active: ccTLD is DNSSEC signed with DNSKEY present in zone and DS present in root zone.

Growth of DNSSEC Active ccTLDs in Africa

Select the sub-region to see its DNSSEC status:

DNSSEC Active
DNSSEC Signed - Not active
No DNSSEC
Eastern Africa

DNSSEC Status Distribution Per Region

Sub-regions

Date to Visualize

i
ccTLD Country DNSSEC Signing Status KEY-ID Algorithm Date of First DNSKEY Records Date of First DS Records

Root zone signed :

2010/07/15

Seen at: 2026/03/18 19:51:15

Script runs every day at midnight (00:00 UTC). For any questions/comments, contact info@cda.africa

Loading...