DNSSEC is short for DNS Security Extensions and very important to us. Therefore everything is capable and DNSSEC-enabled by default in the Lightning Wire Labs DNS services.
DNSSEC will cryptographically sign every response of the name server, so that the client that requested it is able to verify that the DNS response has not been damaged or willingly modified by anyone on its way.
This guarantees that you are communicating with the right servers and it even enables you to store much more interesting information in DNS records, like SSH fingerprints or certificates.
The Lightning Wire Labs DNS service offers a lot of different operation modes and algorithms, which you will find all in the DNSSEC Specifications.
Is it hard to manage?
No. In the Lightning Wire Labs DNS Service, you will just need to enable DNSSEC and it will take care of the rest for you.