I have followed this tutorial to configure DNSsec:
If you don't modify your zone, do you ever need to redo anything like in case of letsencrypt or other certificates they need renewal?
I have these 2 zone files recreated daily by bind automatically, there is no cron task for it so I assume bind does this automatically every day.
-rw-r--r-- 1 _bind _bind 22853 Mar 28 09:11 domain.se.signed
-rw-r--r-- 1 _bind _bind 78526 Mar 28 08:59 domain.se.signed.jnl
auto-dnssec maintain, which really is the sensible option. Also see https://ftp.isc.org/isc/dnssec-guide/html/dnssec-guide.html#easy-start-guide-for-authoritative-servers for a brief guide on that. – Håkan Lindqvist Mar 29 '21 at 11:44