# PUT /api/v1/domains/{domain}/dnssec/auto

> Set DNSSEC auto-management

- Group: domains
- Tier: W
- Required scope: write:domains
- Docs: https://api.inleed.com/reference/domains/set-dnssec-auto

## Description

Validates ownership, then asks the registry (via the client area) to manage the domain's DNSSEC keys automatically. The client area reports the capability honestly when the registrar does not support a headless toggle.

## Path parameters

- `domain` — string (required)

## Body

- `enabled` — boolean

## Request

```bash
curl -X PUT "https://mcp.inleed.com/api/v1/domains/example.se/dnssec/auto" \
  -H "Authorization: Bearer inl_live_…" \
  -H "Content-Type: application/json" \
  -d '{"enabled":true}'
```

## Errors

- **400**  — codes: invalid_request
- **401** No token was presented, or the token is revoked, expired or unknown. — codes: unauthorized, token_expired, token_revoked
- **403** The token lacks a required scope, or this account does not own the resource. — codes: insufficient_scope, not_owned
- **404** No such resource for this account. — codes: not_found
- **422** Validation error — codes: validation_failed
- **429** The rate limit for this token is exhausted. See `Retry-After`. — codes: rate_limited
- **500** Something went wrong on our side. The failure is logged against `requestId`. — codes: internal_error

## Related

- GET /api/v1/domains — https://api.inleed.com/reference/domains/list-domains
- GET /api/v1/domains/{domain}/dnssec — https://api.inleed.com/reference/domains/list-domain-dnssec
- GET /api/v1/domains/{domain} — https://api.inleed.com/reference/domains/get-domain
- POST /api/v1/domains/{domain}/dnssec — https://api.inleed.com/reference/domains/manage-dnssec

