A broken DNSSEC chain does not degrade gracefully. Validating resolvers stop answering entirely, which means a mismatch between your DS record and your zone keys takes a domain offline for a large part of the internet.
Continuous validation
DNSense now validates the chain of trust for every signed zone you manage and alerts you when something drifts.
- DS record compared against the published keys
- Warnings before signatures expire
- Alerts by email, per space
During a provider move
Key rollovers around a provider migration are the most common way to break signing. The zone overview now flags a signed zone before you move it, so the DS record is updated in the right order.

