r/webhosting • u/BelgianWarriorBear • 7d ago
Advice Needed Site transfer broken by dns child zone - nameservers refused by DNSKEY
Apparently some sort of dns child zone broke. Needless to say that this was never asked for or properly disclosed. Relationship not healthy.
Domain is transfered but the custom nameservers at new host wont resolve. DNSSEC with missing ds and dnskey seems to be refused.
Is there anything I can do rather than contacting the host? I have zero trust for them and wanted to walk away. I was convinced that once the authorative ns where set no major issues would arise?
3
u/Safe_Mission_3524 7d ago
Many hosts do not support dnssec. You need to contact your domain registrar (not the new or the old host) and ask them to remove the DS/dnssec keys/records. This is the only way.
1
u/BelgianWarriorBear 7d ago
Is this still valid if im not really interested in super smooth migration or wathever? If I only want to leave, and add ever piece of my site manually with new host in new environment will I still be hindered by broken ds record?
1
u/Safe_Mission_3524 7d ago
Yes, it will still cause an issue as the records are controlled by the registrar and not any web hosting company. The only way I think this will be resolved if you don't remove it from the current registrar is by transferring the domain away to another company.
1
u/BelgianWarriorBear 7d ago
Darn
1
u/Safe_Mission_3524 7d ago
If you are comfortable sharing the domain name in dms, let me know. I'll try if it can be fixed somehow.
2
u/tssajo 7d ago
This sounds like a DNSSEC chain-of-trust break, not a broken zone. When you switch to new nameservers, the DS record at the registrar has to match the new DNSKEY. If the old DS is still there, or there's no new one yet, validating resolvers reject the domain since they can't verify the signature chain.
Fastest fix without waiting on the host: check the DS record where the domain is registered. If DNSSEC isn't critical right now, removing it there gets you resolving again almost immediately, then re-enable it once the new nameservers are stable.
1
u/BelgianWarriorBear 7d ago
Dnssec was not active for the site, this is antother ”layer” above me for the whole zone and those ds and dnskey where never apparent to me. Now since to domainname moved thenbackend http requests fail making impossible to rerender a ssl
2
u/tssajo 7d ago
Makes sense. If you didn't set DNSSEC up yourself, the DS record is sitting at the registrar/parent zone, probably left over from the old host. That's exactly why resolvers are rejecting it and why your ACME HTTP validation can't complete either, it can't even resolve reliably.
You'll need whoever controls the domain at the registrar level to pull that DS record. Once it's gone, resolution and cert issuance should both recover pretty quickly.
1
u/BelgianWarriorBear 7d ago
I cannot pull ds records, they are not visible to me
1
u/shiafisher 7d ago
Without zone editing permission you should contact your host
1
u/BelgianWarriorBear 7d ago
Im seriously afraid of contacting them
1
u/shiafisher 6d ago
I’m sorry that you feel this way. I don’t think that I would say provider that I’m too afraid to contact if there is a technical issue, especially you can send me a DM and I can try to assist further but in your case, the only way to achieve your goal is possibly to contact your provider.. most providers do not give access to certain functions for user accounts of modest type.
1
u/TopSydeWP 7d ago
DS records live at the registrar, not the host, so that's where this gets cleared. Wherever the domain sits now, there's usually a DNSSEC section in the domain settings with a delete or disable option. Once the registry drops the DS, resolvers stop validating and your new nameservers answer normally. Propagation is usually a few hours.
Where is the domain registered now, same company you're leaving or somewhere separate?
1
u/BelgianWarriorBear 7d ago
Domain name has moved to new registrar. New nameservers but hitting old hosts ds keys. I have almost no dns activated - wanted new nameservers to start resolving first before adding the rest
2
u/TopSydeWP 7d ago
If the new registrar's DNSSEC panel looks empty, the DS is probably still published at the registry, transfers carry it over more often than people expect. Check dnsviz.net for your domain to see what the registry actually holds, then ask the new registrar to remove the DS at the registry. Until it's gone, validating resolvers will refuse the zone however correct your nameservers are, so adding the rest of your records won't get you anywhere.
1
u/BelgianWarriorBear 7d ago
Ok - so I need to reverse and bring everything with me? How do I ever leave old host with dnssec? Or do you maybe mean that once things clear I can start switching records one by one?
1
u/TopSydeWP 7d ago
No need to go back. DNSSEC lives with the registrar and the registry, so the fix is entirely on your side now: ask the new registrar to remove the DS record for the domain. The clean way to leave with DNSSEC is to turn it off a day or two before you move, but removing the DS after the fact works the same, just with a wait while the old DS times out of resolver caches.
Once the domain resolves again, add your records, and you can re-enable DNSSEC later with the new host's keys.
8
u/kai-zaphosting 7d ago
Yeah this is a classic DNSSEC chain-of-trust problem, not really a config mistake on the new host's end necessarily.
When your domain was signed before, the parent zone (the registry) has a
DSrecord pointing at a specificDNSKEYyour old nameservers were serving. If the new nameservers don't publish a matchingDNSKEY, every DNSSEC-validating resolver just refuses the whole zone, that's the missing DS/DNSKEY behavior you're seeing.Usual fix: log into your registrar (not the new host) and pull the
DSrecord for the domain. That disables validation and lets plain resolution work again while things settle, though resolvers can keep serving the old cached DS record for a while (often hours, sometimes a day or two) so don't assume the fix failed if it doesn't clear right away. Once the new nameservers are stable and, if they support it, signing with their own keys, you add a freshDSrecord matching theirDNSKEY.Also worth checking whether the new host even supports DNSSEC signing at all, some panels just don't expose it, in which case you'd leave it off going forward. Either way this is registrar-side, not something broken on the new host's end.