DNS Issues

DNSSEC Validation Failure

DNSSEC validation failures occur when the cryptographic chain of trust between the parent zone and child zone is broken. This can happen due to expired RRSIG signatures, missing or incorrect DS records at the registrar, key rollovers gone wrong, or algorithm mismatches. When DNSSEC validation fails, validating resolvers will return SERVFAIL instead of the DNS response.

Symptoms

  • Domain resolves on some resolvers but returns SERVFAIL on validating resolvers (e.g., 8.8.8.8)
  • DNSSEC-aware clients cannot reach the website
  • dig +dnssec shows expired or invalid signatures

Common Causes

  • RRSIG signatures expired and not re-signed
  • DS record at registrar doesn't match DNSKEY in zone
  • Key rollover performed incorrectly
  • NSEC/NSEC3 chain broken

Step-by-Step Troubleshooting

  1. 1

    Check DNSSEC status

    Verify DNSSEC signatures and chain of trust for the domain.

    Use DNSSEC Check β†’
  2. 2

    Inspect DS records

    Compare DS records at the parent zone with DNSKEY records in the child zone.

    Use DS Record Lookup β†’
  3. 3

    Verify DNSKEY records

    Check that DNSKEY records are properly published and match the DS delegation.

    Use DNSKEY Lookup β†’

Recommended Diagnostic Tools

Monitor DNSSEC

Get alerts before DNSSEC signatures expire or validation breaks.

Frequently Asked Questions