DNS Management & Nameservers

Analyzing and Resolving DNSSEC Problems: A Comprehensive Guide

By the Domain India teamPublished 6 min read
Knowledge base article
Contents (4 sections)

When DNSSEC is set up wrongly, a domain does not fail everywhere at once: it works on some internet connections and returns an error on others. That pattern is the signature of a DNSSEC fault, usually a DS record at the registry that no longer matches the keys in your DNS zone. This page shows how to confirm it in a few minutes and what to do next.

Key takeaways

If your domain loads on some networks but shows "server not found" or SERVFAIL on others, check DNSSEC first. Run dig DS yourdomain.in +short and test the domain on DNSViz. A DS record that does not match your zone's DNSKEY must be corrected or removed at the registry. For a domain registered with Domain India, there is no DS record page in the client area, so open a support ticket.

For the full guide

How DNSSEC works, how to sign a zone and how to run it safely is covered in DNSSEC explained. For domains registered with us, see implementing DNSSEC on DomainIndia.com. This page is the troubleshooting short version.

1. Why the domain works on some connections but not others

Resolvers that validate DNSSEC, such as Google Public DNS, Cloudflare's 1.1.1.1, Quad9 and many ISP resolvers, check the signatures on every answer. If the DS record at the registry points to a key your zone no longer has, or the signatures have expired, they reject the answer and return SERVFAIL. Resolvers that do not validate ignore DNSSEC and answer normally. Cached answers can keep a broken domain working for some users for a few hours.

2. Confirm it in three commands

bash
# 1. Is a DS record published for the domain?
dig DS yourdomain.in +short

# 2. Does the zone publish matching keys? (compare the key tag with the DS record)
dig DNSKEY yourdomain.in +dnssec +multi

# 3. Does a validating resolver fail while validation-off succeeds?
dig A yourdomain.in @1.1.1.1
dig A yourdomain.in @1.1.1.1 +cd

If the normal query returns SERVFAIL and the +cd (checking disabled) query returns your IP address, DNSSEC validation is the cause. Then check the domain on DNSViz (dnsviz.net) or Verisign's DNSSEC Analyzer: both show the whole chain of trust and highlight the broken link in red.

3. Common faults and the fix

What you seeLikely causeFix
Works on some networks, SERVFAIL on othersDS record does not match the zone's DNSKEYCorrect or remove the DS record at the registry
Everything failed right after moving DNS or nameserversThe old DS record still points to the previous provider's keyRemove the DS record, wait, then set DNSSEC up again at the new DNS host
Worked for months, then failedSignatures (RRSIG) expired because the zone stopped being re-signedFix signing at the DNS host, or remove the DS record until it is fixed
dig DS shows nothingNo DS record, so DNSSEC is not activeNothing is broken; DNSSEC is simply off
Removing a broken DS record is the fastest safe fix

If you cannot correct the keys quickly, removing the DS record at the registry takes the domain back to ordinary, unsigned DNS, which every resolver accepts. Validating resolvers may keep the old answer until caches expire, often a few hours up to about a day. Never add a new DS record until the zone is actually signed with the matching key.

4. Fixing it for a domain registered with Domain India

The DS record lives at the registry and is changed through the registrar, never in a hosting control panel's DNS zone editor. There is no DNSSEC or DS record page in the Domain India client area.

  1. Find who hosts your DNS.
    Run dig NS yourdomain.in +short. That provider signs the zone and holds the keys.
  2. Collect the evidence.
    Save the output of the commands above and a DNSViz link.
  3. Open a ticket.
    Go to open a ticket (or /client/support/new when signed in) with the domain name, your DNS provider and whether you want the DS record corrected or removed. Support will tell you what is possible for that domain before anything is changed.
  4. Check again.
    Once support confirms the change, repeat the tests.

If your domain is registered elsewhere, make the same change in that registrar's DNSSEC settings. Before you move a signed domain to new nameservers, remove the DS record first, wait a day or two, and only then change the nameservers; see how do I change my nameservers.

Why does my domain work on mobile data but not on my office Wi-Fi?

Different networks use different DNS resolvers. If DNSSEC is broken, resolvers that validate signatures reject the domain, while resolvers that do not validate still answer. A DS record that does not match the zone's keys is the usual cause.

How do I check whether DNSSEC is causing the problem?

Run dig A yourdomain.in @1.1.1.1 and then the same command with +cd added. If the first returns SERVFAIL and the second returns an IP address, DNSSEC validation is failing. DNSViz shows exactly which link in the chain is broken.

Is it safe to remove DNSSEC from my domain?

Yes, if it is done by removing the DS record at the registry first. The domain then resolves as ordinary unsigned DNS. Remove the keys at the DNS host only after the DS record is gone and caches have expired.

Can I change the DS record in the Domain India client area?

No. There is no DNSSEC or DS record page in the client area. Open a support ticket with the domain name and your DNS provider, and support will tell you what is possible before anything is changed.

Ready to fix it? Run the checks above, read DNSSEC explained for the background, and open a ticket with your results if the domain is registered with us.

Domain failing on some networks?

Send the domain name, your DNS provider and the output of the dig commands, and our support team will check the DS record with you.

Open a ticket

Ready when you are

Find your domain

Search domains

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
DNSSEC Problems: Diagnose and Fix a Broken DS Record