DNSSEC lets validating resolvers check signed DNS data against a chain of trust. It needs both signing at your DNS provider and the matching DS information at the domain's parent registry. An enabled signing switch alone does not confirm that the public chain is complete.
IN THIS ARTICLE
01 Before enabling DNSSEC
Confirm the domain uses the DNS service you intend to sign, that its ordinary records resolve correctly and that you can manage DS information at its registrar. DNSSEC must be included in your package and supported by the server handling your zone. If the tab is missing, ask support to check those conditions.
02 Enable and verify
- Open the correct domain in DNS Manager and select DNSSEC.
- Choose the available enable action and wait for the DNS backend to finish signing.
- Refresh the status and obtain the generated DS values.
- Check whether your registrar workflow has already published the matching DS. When manual action is required, enter the exact key tag, algorithm, digest type and digest supplied by the DNS provider.
- Confirm the registrar saved the DS and use the manager's status checks or support to verify the live chain.
A DS value displayed for copying is not proof that the registrar has published it. Conversely, a parent DS pointing to old keys can make a zone fail validation even when its A and MX records look correct in the editor.
03 Disable DNSSEC carefully
Coordinate removal of the parent DS before switching off the old signing service. Allow the relevant cached DS data to expire and follow the provider's disable workflow. If you turn off signing while resolvers still rely on the old DS, users of validating resolvers may be unable to reach the domain.
04 When moving to another DNS provider
Prepare the destination records and plan the DNSSEC transition separately from the nameserver change. Do not copy old private keys, DNSKEY records or DS values into ordinary record fields as a shortcut. The new provider issues its own signing material, and the parent must eventually refer to the correct destination keys. Some providers offer coordinated methods; use only a procedure supported by both sides.
What should I check if the domain stops resolving after a DNSSEC change?
Report any SERVFAIL result, the current nameservers, recent DNSSEC or registrar changes and the time of the change. Do not generate several new key sets while troubleshooting. Support can compare the live parent DS with the actual DNSKEY and signatures and identify the specific mismatch.