DNSSEC is not currently available on Tudor Internet’s standard InterWorx nameservers.
DNSSEC allows validating resolvers to confirm that DNS answers have not been altered. It requires coordination between the authoritative DNS provider, which signs the zone, and the registrar or registry, which publishes the DS record in the parent zone.
Check whether DNSSEC can be used
- Identify the domain’s authoritative nameservers using the registrar, a WHOIS/RDAP service or an external DNS lookup.
- If the nameservers are Tudor Internet’s standard InterWorx nameservers, leave DNSSEC disabled and do not add a DS record.
- If an external DNS provider is authoritative, confirm that it supports DNSSEC for the domain and can provide DS record data.
- Confirm that you are authorised to change both the DNS zone and the domain’s registrar settings.
Enable DNSSEC with an external DNS provider
- At the external DNS provider, enable DNSSEC or zone signing for the domain.
- Wait until every authoritative nameserver returns matching DNSKEY and RRSIG records.
- Copy the complete DS record exactly. It normally contains a key tag, algorithm, digest type and digest.
- For a domain registered with Tudor Internet, open a support ticket and provide the DS record. For a domain registered elsewhere, add the DS record through that registrar.
- After the registry publishes the DS record, validate the chain from the parent zone to the authoritative nameservers using an independent DNSSEC checker.
- Test the website, email and other DNS-dependent services from more than one network.
Changing nameservers
When moving a DNSSEC-enabled domain to a provider that does not sign the zone, remove the DS record at the registrar before changing nameservers. Wait for the parent-zone TTL to expire and confirm the DS record has disappeared before completing the move.
Disable DNSSEC safely
- Remove the DS record from the registrar or ask Tudor Internet Support to remove it.
- Wait until the parent zone no longer returns the DS record and cached copies have expired.
- Only then disable signing or remove the DNSSEC keys at the DNS provider.
- Confirm the domain resolves normally through several validating resolvers.
Common problems
| Symptom | Likely cause | What to do |
|---|---|---|
| The domain returns SERVFAIL on some or all networks | The parent DS record does not match the active DNSKEY, signatures have expired, or one nameserver serves different data. | Compare the live DS, DNSKEY and signatures. Restore the matching signed zone or remove the DS through a controlled rollback. |
| The domain works before the DS is added but fails afterward | The zone was not fully signed or the wrong DS record was submitted. | Remove the incorrect DS record, allow caches to expire and revalidate the unsigned domain before trying again. |
| A nameserver change caused DNSSEC failure | A DS record from the previous DNS provider remains in the parent zone. | Remove the stale DS record and wait for the parent TTL before relying on the new unsigned nameservers. |
When to contact Tudor Internet
Open a support ticket before publishing or removing a DS record for a domain registered with Tudor Internet. Include the full domain name, authoritative nameservers, the complete DS record supplied by the DNS provider and the planned change window.
Related articles
- Change a domain’s nameservers
- Manage DNS records
- Set up SPF, DKIM and DMARC records
- Diagnose NXDOMAIN and SERVFAIL DNS errors
Last reviewed: 2026-07-25.