Skip to main content
Stackryze treats security as a default, not an upsell. Every account gets strong defaults; verification unlocks advanced controls.

Defaults for everyone

ControlFreeNotes
TLS 1.3 on the dashboardHSTS preloaded
TOTP-based 2FARecommended for every account
WebAuthn / passkeysFirst-class, not a beta
Per-zone audit log30 daysForever on verified
IP allowlist for API tokensAvailable with verification

DNSSEC

DNSSEC lets resolvers cryptographically verify that answers actually came from your zone — defeating the kind of cache poisoning that took down whole registrars in 2024. Stackryze signs every enabled zone with ECDSA P-256 + SHA-256 by default. NSEC3 with opt-out is enabled to prevent zone-walking. To turn DNSSEC on for a zone you own:
  1. Open the zone in the dashboard
  2. Go to Settings → DNSSEC
  3. Click Enable
  4. Copy the DS record we generate
  5. Paste it at your registrar
See the full walkthrough in Enable DNSSEC.

Compliance