---
title: "Update domain to use NSEC3"
method: GET
path: "/DNSSEC/set_nsec3"
tags: ["DNSSEC", "DNS Security"]
---

# Update domain to use NSEC3

`GET /DNSSEC/set_nsec3`

This function configures the domain to use [Next Secure Record 3](https://tools.ietf.org/html/rfc4470) (NSEC3) semantics.

**Important:**

  When you disable the [DNS role](https://go.cpanel.net/howtouseserverprofiles#roles), the system **disables** this function.

## Query parameters

- `domain` string, domain, required
- `nsec3_iterations` integer, required
- `nsec3_narrow` 0 | 1, required
- `nsec3_opt_out` 0 | 1, required
- `nsec3_salt` string, hex, required

## Response `200`

HTTP Request was successful.

- object
  - `apiversion` integer — The version of the API.
  - `func` string — The name of the method called.
  - `module` string — The name of the module called.
  - `result` object
    - `data` object
      - `enabled` object — Contains the domains for which the system enabled NSEC3. **Note:** This return's name is the `domain` parameter's value.
    - `errors` string[], nullable — List of errors if the API failed.
    - `messages` string[], nullable — List of messages generated by the API.
    - `metadata` object
    - `status` 0 | 1 — - 1 - Success - 0 - Failed: Check the errors field for more details.
    - `warnings` string[], nullable — List of warnings generated by the API. Warnings describe non-critical failures or other problematic conditions noted while running a API.

---

[API](https://skmtc.net/cpanel/apis/cpanel-uapi.md) · [All operations](https://skmtc.net/cpanel/apis/cpanel-uapi/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/cpanel/cpanel-uapi/revisions/632e2f8e6d04/schema)
