Turning DNSSEC off is the reverse of turning it on, and the order is not a preference. Get it backwards and the domain stops resolving for everyone using a validating resolver.
Why order matters
While the DS record is published at the registry, every validating resolver expects your zone to be signed. Unsign it first and those resolvers ask for signatures, find none, and conclude the answer has been tampered with. They return SERVFAIL, and the domain is gone.
Removing the DS first tells the world to stop expecting signatures. Only once no resolver still holds that expectation is it safe to unsign.
The sequence
- Remove the DS record at your registrar. Not here — at the registrar, in the same place you added it.
- Wait for the DS TTL to expire. The parent zone sets it and you do not control it; a day is a safe assumption, and
dig DS example.comtells you what is left. - Confirm it is gone from the parent:
dig +short DS example.com
Nothing back, and the wait done, means no validator still expects a signature.
- Then unsign — Zones → your zone → DNSSEC → Disable DNSSEC.
Why the wait cannot be skipped
Removing the DS at the registry does not remove it from resolvers that already fetched it. They keep their copy until the TTL runs out, and during that window they still demand signatures.
Unsigning inside that window breaks the domain for exactly the people whose resolvers had cached the DS — which is to say, the ones who visit you most often.
If you have already unsigned in the wrong order
The domain is likely failing right now for validating resolvers. The fastest fix is one of:
- Re-sign the zone, which restores signatures the published DS can still validate. Only reliable if the same keys are in use.
- Remove the DS at your registrar and wait for its TTL. This always works, but the wait is the wait.
Removing the DS is the safer of the two, because it ends in a clean unsigned state rather than a signed one you were trying to leave.
Related
Last reviewed 2026-09-16.
Open a ticket from the control panel, or use the contact form if you cannot sign in. If a domain is down, the status page is the fastest way to find out whether it is us.