DNSSEC lets validating resolvers check DNS data against a chain of trust. It is separate from HTTPS and does not encrypt website traffic. A mismatch between the parent zone's DS record and the DNS provider's signing keys can make a domain fail to resolve. See Cloudflare's DNSSEC overview.
Neither the registrar controls under Domains nor the hosting DNS & SSL editor currently provides self-service DNSSEC or DS-record changes. Selecting Use Lucid nameservers does not migrate existing DS records. Coordinate these operations with support and the authoritative DNS provider.
- Before changing nameservers, transferring a signed domain, or retiring a DNS provider, ask whether DNSSEC is active and whether a DS record is published at the registry.
- Identify the current DNS provider, the intended new provider, and which party can manage the domain's DS records.
- Ask support for a coordinated migration sequence. Depending on provider capabilities, this may involve a supported signed migration or a planned temporary removal of the old delegation's trust information. Do not independently switch off signing while an old DS record still expects it.
- Supply the requested public DNSSEC parameters through the approved support process. Do not send private signing keys.
- Complete the nameserver or provider change only at the agreed stage, then have support verify DNS resolution and validation.
- If signing is enabled at the destination, confirm that the final DS information matches the active signing configuration and that validation succeeds.
What does successful completion look like? The website and email work through validating resolvers, and the intended DNSSEC state is confirmed. A domain that works through one resolver but returns SERVFAIL through another needs investigation rather than a blanket instruction to wait.
If the domain stops resolving after a change: Give support the domain, old and new nameservers, change time, and the exact lookup error. Mention any recent DS or signing changes. Avoid making further uncoordinated changes; the required fix depends on which part of the chain is inconsistent.
If DNSSEC is unavailable for your setup: Ask support to confirm the supported options. The absence of a control in the customer account should not be interpreted as proof that DNSSEC is either enabled or disabled.
Related: Change nameservers, Troubleshoot DNS, Plan a hosting move.


Leave a Reply