Enable DNSSEC and complete the DS-record setup

DNSSEC lets validating resolvers check signed DNS data against a chain of trust. It needs both signing at your DNS provider and the matching DS information at the domain's parent registry. An enabled signing switch alone does not confirm that the public chain is complete.

01 Before enabling DNSSEC

Confirm the domain uses the DNS service you intend to sign, that its ordinary records resolve correctly and that you can manage DS information at its registrar. DNSSEC must be included in your package and supported by the server handling your zone. If the tab is missing, ask support to check those conditions.

02 Enable and verify

  1. Open the correct domain in DNS Manager and select DNSSEC.
  2. Choose the available enable action and wait for the DNS backend to finish signing.
  3. Refresh the status and obtain the generated DS values.
  4. Check whether your registrar workflow has already published the matching DS. When manual action is required, enter the exact key tag, algorithm, digest type and digest supplied by the DNS provider.
  5. Confirm the registrar saved the DS and use the manager's status checks or support to verify the live chain.

A DS value displayed for copying is not proof that the registrar has published it. Conversely, a parent DS pointing to old keys can make a zone fail validation even when its A and MX records look correct in the editor.

03 Disable DNSSEC carefully

Coordinate removal of the parent DS before switching off the old signing service. Allow the relevant cached DS data to expire and follow the provider's disable workflow. If you turn off signing while resolvers still rely on the old DS, users of validating resolvers may be unable to reach the domain.

04 When moving to another DNS provider

Prepare the destination records and plan the DNSSEC transition separately from the nameserver change. Do not copy old private keys, DNSKEY records or DS values into ordinary record fields as a shortcut. The new provider issues its own signing material, and the parent must eventually refer to the correct destination keys. Some providers offer coordinated methods; use only a procedure supported by both sides.

What should I check if the domain stops resolving after a DNSSEC change?

Report any SERVFAIL result, the current nameservers, recent DNSSEC or registrar changes and the time of the change. Do not generate several new key sets while troubleshooting. Support can compare the live parent DS with the actual DNSKEY and signatures and identify the specific mismatch.

Sources and further reading

  • 0 Users Found This Useful
  • domains-dns, domain-nexus
Was this answer helpful?

Related Articles

Back up and restore DNS records

A DNS backup records the zone's entries so you can review or restore a previous configuration....

Use bulk DNS changes across one or several zones

Bulk management is useful when several records need the same new address or TTL. It also...

Add a domain registered elsewhere to your DNS Manager

You can manage DNS for a domain registered with another company when your Nabtech service...

Read a DMARC aggregate report in DNS Manager

The Premium DNS Plus report reader helps you inspect a DMARC aggregate report received from an...

Create a website redirect with Domain Forwarders

Domain forwarding sends a visitor from your domain to another web address. An ordinary redirect...