DNS Issues
DNSSEC Validation Failure
DNSSEC validation failures occur when the cryptographic chain of trust between the parent zone and child zone is broken. This can happen due to expired RRSIG signatures, missing or incorrect DS records at the registrar, key rollovers gone wrong, or algorithm mismatches. When DNSSEC validation fails, validating resolvers will return SERVFAIL instead of the DNS response.
Symptoms
- Domain resolves on some resolvers but returns SERVFAIL on validating resolvers (e.g., 8.8.8.8)
- DNSSEC-aware clients cannot reach the website
- dig +dnssec shows expired or invalid signatures
Common Causes
- RRSIG signatures expired and not re-signed
- DS record at registrar doesn't match DNSKEY in zone
- Key rollover performed incorrectly
- NSEC/NSEC3 chain broken
Step-by-Step Troubleshooting
- 1
- 2
Inspect DS records
Compare DS records at the parent zone with DNSKEY records in the child zone.
Use DS Record Lookup β - 3
Verify DNSKEY records
Check that DNSKEY records are properly published and match the DS delegation.
Use DNSKEY Lookup β
Recommended Diagnostic Tools
Monitor DNSSEC
Get alerts before DNSSEC signatures expire or validation breaks.

