How to fix DNSSEC (DS records) at Porkbun

The DS record at your registrar tells the world your zone is DNSSEC-signed, and by which key. When it goes stale — classically after switching DNS providers — validating resolvers (Google 8.8.8.8, Cloudflare 1.1.1.1, most ISPs) return SERVFAIL and your site goes dark for those users while everything looks fine on your end.

Switching DNS providers on a DNSSEC-signed domain? Remove the DS record (or disable DNSSEC) at the registrar FIRST, and keep the old zone signed until the DS TTL has fully expired — changing nameservers while the old DS is cached makes validating resolvers return SERVFAIL (per Cloudflare's DNSSEC documentation).

Turning DNSSEC on (managed)

Using Porkbun's default nameservers: Domain Management → Details dropdown → "Porkbun DNSSEC" one-click toggle.

Managing DS records manually (external DNS)

  1. With third-party DNS: Domain Management → Details dropdown → "Registry DNSSEC" → edit icon → Create DNSSEC Record (Key Tag, Algorithm, Digest Type, Digest).

Fixing a broken (bogus) chain

  1. Confirm the break: our DNSSEC checker (or DNSViz) shows whether the DS at the registry matches the keys your DNS provider is actually signing with.
  2. If you recently changed DNS providers: either publish the NEW provider's DS record here (get the values from their dashboard), or remove the DS entirely to unsign the domain — resolvers recover as caches expire.
  3. If the DS is right but signatures expired, the fix is at your DNS provider (re-signing), not the registrar.

Some ccTLD registries (.eu, .de, .nl) take key data instead of DS digests — Porkbun's form follows the registry.

Steps verified against Porkbun: install DNSSEC and related Porkbun docs on 2026-07-14.

Validate the chain right now

The free DNSSEC checker validates your chain the way real resolvers do and pinpoints the broken link — run it after any DS change.

Run the DNSSEC check →