---
title: "Create domain's DNSSEC zone key"
method: GET
path: "/add_zone_key"
tags: ["DNS", "DNS Security"]
---

# Create domain's DNSSEC zone key

`GET /add_zone_key`

This function generates a DNSSEC zone key for a domain.

**Note:**

* Only servers that run PowerDNS can use DNSSEC. If you call this function on
a server that doesn't use PowerDNS, you will receive an error.
* After you enable DNSSEC on the domain, you **must** add the Delegation of Signing (DS)
records to your zone record and your registrar.
* You **cannot** modify the DNSSEC security key. To make any changes, you **must** disable,
delete, and re-create the DNSSEC security key.

## Query parameters

- `algo_num` 5 | 6 | 7 | 8 | 13 | 14, required
- `domain` string, required
- `key_type` string, required
- `active` 0 | 1
- `key_size` 256 | 384 | 1024 | 2048

## Response `200`

HTTP Request was successful.

- object
  - `data` object
    - `new_key_id` string — The security key's ID.
  - `metadata` object
    - `command` string — The method name called.
    - `reason` string — The reason the API function failed when the `metadata.result` field is `0`. This field may display a success message when a function succeeds.
    - `result` 0 | 1 — * `1` — Success. * `0` — Failed. Check the `reason` field for more details.
    - `version` integer — The version of the API function.

---

[API](https://skmtc.net/cpanel/apis/whm-api.md) · [All operations](https://skmtc.net/cpanel/apis/whm-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/cpanel/whm-api/revisions/3da41671c02c/schema)
