Big protection. Even on the free plan. Meet your new DNS home
KumoDNS
Documentation

Moving a signed domain to another provider

A signed domain cannot simply be re-delegated — the safe route goes unsigned in the middle, and the alternative needs both providers to cooperate.

Migrating an unsigned domain is a matter of copying records and changing nameservers. Migrating a signed one has an extra constraint that will take the domain off the internet if it is ignored.

Why you cannot just switch

The DS record at your registry is a fingerprint of the key your current provider holds. The new provider will sign with a different key.

Change the nameservers with the old DS still published, and every validating resolver asks the new nameservers for records that match the old key. They do not. The domain does not degrade — it becomes unresolvable.

The safe route: go unsigned in the middle

This works with any two providers and needs nothing from either of them.

  1. Remove the DS record at your registrar.
  2. Wait for the DS TTL to expire — the parent sets it and a day is a safe assumption. During this window the domain is still signed and still validating; you are only withdrawing the expectation.
  3. Confirm it is gone: dig +short DS example.com returns nothing.
  4. Migrate normally — copy the zone, verify every record against the new nameservers, change the delegation at the registrar. See importing and exporting zone files.
  5. Sign at the new provider once you are confident the zone is correct there.
  6. Publish the new DS at your registrar.

The domain is unvalidated between steps 2 and 6. That is a real reduction in protection for a day or two, and it is still far better than the alternative of being unreachable.

The alternative, and why most people should not attempt it

There is a way to migrate without going unsigned: both providers publish each other's DNSKEY records for the duration, so signatures from either validate against a DS covering both keys.

It requires the old provider to import a key from the new one, both to keep it published through the change, and a careful sequence on both sides. If either provider does not document this explicitly, it is not worth attempting — the failure mode is the same outage you were avoiding, with more steps to unwind.

Coming to KumoDNS from a signed domain elsewhere

Same sequence, from your side:

  1. Remove the DS at your registrar, and wait out its TTL.
  2. Import the zone file here and check the records.
  3. Point the registrar at our nameservers, and leave the old provider serving for a week.
  4. Sign the zone here, then publish the new DS.

Sign last. Signing before the delegation has settled means resolvers that still ask the old provider get unsigned answers while the parent points at a signed zone — the mismatch in miniature.

Last reviewed 2026-09-16.

Not what you needed?

Open a ticket from the control panel, or use the contact form if you cannot sign in. If a domain is down, the status page is the fastest way to find out whether it is us.

Top