highest value of the `change_date` field in the "records" table.
-# Handeling DNSSEC signed zones
+# Handling DNSSEC signed zones
To enable DNSSEC processing, the `backend-dnssec` option must be set to 'yes'.
## Rules for filling out DNSSEC fields
**Warning**: Once the relevant `backend-dnssec` switch has been set, stricter
rules apply for filling out the database! The short version is: run
`pdnsutil rectify-all-zones`, even those not secured with DNSSEC! For more
-information, see the [DNSSEC documentation for Generic SQL backends](backend-generic-sql.md#handeling-dnssec-signed-zones).
+information, see the [DNSSEC documentation for Generic SQL backends](backend-generic-sql.md#handling-dnssec-signed-zones).
To deliver a correctly signed zone with the [DNSSEC defaults](#dnssec-defaults),
invoke: