DNSSEC help

DNSSEC SERVFAIL and DS record problems

DNSSEC failures can make an otherwise correct zone appear completely broken to validating resolvers. A common class of incidents happens when DS data at the registrar no longer matches the keys used by the authoritative DNS provider.

SERVFAIL diagnosis

Determine whether validating resolvers fail because of the DNSSEC chain rather than ordinary record absence.

DS mismatch

Compare parent-zone DS information with the current DNS provider configuration.

Provider migration

Check whether DNSSEC was disabled, re-enabled or migrated in the wrong order.

Safe recovery

Avoid random record edits when the failure is in the chain of trust rather than the zone contents.

Need a human diagnosis?
A paid SaveMyDNS diagnostic focuses on your actual domain and incident rather than a generic checker result.
View DNS Diagnostic