Skip to content

DNS host provides a DS record, registrar refuses or asks for different fields

The DS record bridges registrar (parent zone) and DNS host (child zone) for DNSSEC. Each registrar asks for it in their own form: key tag, algorithm, digest type, digest. One wrong field and the chain does not validate.

Try this first

  1. 1Get the full DS record from the DNS host: key tag (a number), algorithm (8=RSA-SHA256, 13=ECDSA-P256), digest type (1=SHA1, 2=SHA256), and the digest string itself.
  2. 2Fill it in at the registrar: TransIP and Versio have web forms with those four fields, GoDaddy and others accept a BIND-format DS string.
  3. 3Some registrars require the DNSKEY (the key itself, not the digest). The DNS host provides that too.
  4. 4Wait at least 48 hours after submit, some TLD registries (SIDN for .nl) have publication time before the DS lives in the parent zone.
  5. 5Test with dnsviz.net or dnssec-analyzer.verisignlabs.com that the chain is valid before touching anything else in DNS.

When to bring us in

If you have a DS record at the registrar that no longer matches the zone keys, we can guide the rollover so resolvers do not mark the zone as bogus.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.