DNSSEC (DNS Security Extensions) adds cryptographic signatures to DNS records. A validating resolver can confirm that an answer really came from the domain’s authoritative nameservers and wasn’t altered on the way.
The problem it solves
Ordinary DNS answers aren’t signed. In certain attacks, a resolver can be tricked into caching a forged answer that sends visitors to the wrong server. DNSSEC makes forged answers detectable.
The chain of trust
- The domain’s nameservers sign its records with a key.
- A fingerprint of that key — the DS record — is lodged with the registry through your registrar.
- The registry’s own records are signed, and so on up to the DNS root.
A validating resolver follows the chain from the root down.
The danger: a broken chain
If the DS record at the registrar doesn’t match the keys on the nameservers, validating resolvers treat every answer as forged and refuse to resolve the domain. This most often happens when a domain with DNSSEC switches nameservers but the old DS record is left at the registrar.
The symptom: the domain works on some networks and not at all on others, with SERVFAIL errors.
Before changing nameservers
If DNSSEC is enabled at your current DNS provider, turn it off and remove the DS record at your registrar first, wait a day, then switch nameservers. Turning it back on is a separate step once the move is complete.
To see if a domain has a DS record:
dig yourdomain.co.uk DS +short
Any output means DNSSEC is active at the registry level.