DNSSEC uses a system of digital signatures and public keys to verify that DNS responses are authentic and have not been tampered with. When a DNS resolver queries a DNS server, it checks the digital signature against the public key stored in the DNS record. If the signatures match, the data is considered authentic.