Signing a zone does nothing on its own. Until the DS record is published at your registrar, no resolver has any reason to believe your key — so the zone is signed, and validated by nobody.
This is the step people miss, because nothing warns you.
Where to find it
Zones → your zone → DNSSEC. Once the zone is signed, the DS record is shown with all four fields.
What the fields mean
A DS record has four parts:
| Field | What it is |
|---|---|
| Key tag | A short number identifying which key this refers to |
| Algorithm | The signing algorithm — 13 for ECDSA P-256, which is what we use |
| Digest type | The hash used, 2 for SHA-256 |
| Digest | The hash itself, a long hex string |
Registrars ask for it in different shapes
This is where it gets confusing, because there is no single format.
Four separate fields. The most common. Copy each value into the matching box.
One line of text. Some registrars take the whole record. Paste it as shown.
DNSKEY instead of DS. A few registrars want the key and compute the DS themselves. If yours asks for a public key, flags and a protocol number rather than a digest, that is what it wants — the DNSSEC page shows that form too.
If your registrar offers both, either is fine. Give it one, not both.
Confirming the parent published it
Adding it at the registrar is not the same as it being live — the registry has to publish it, which is usually minutes but can be longer.
Check the parent, not your own zone:
dig +short DS example.com
That asks for the DS in the parent zone. Nothing back means it is not published yet.
Then confirm the whole chain validates:
dig +dnssec example.com
Look for the ad flag in the response — authenticated data — which means a validating resolver checked the chain and it held.
If it does not appear
- Wait. Registry publication is not instant, and the parent's own TTL applies afterwards.
- Check you used the right zone. A DS for
example.comadded toexample.netpublishes happily and validates nothing. - Check the digest was pasted whole. A truncated hex string is the most common cause, and it produces exactly the same symptom as a wrong key.
⚠️ A wrong DS is worse than no DS. No DS means the zone is unvalidated; a wrong one means every validating resolver refuses it. If a domain stops resolving after you add a DS, remove it at the registrar — that restores service while you work out what happened.
Related
Last reviewed 2026-09-16.
Open a ticket from the control panel, or use the contact form if you cannot sign in. If a domain is down, the status page is the fastest way to find out whether it is us.