[{"data":1,"prerenderedAt":62},["ShallowReactive",2],{"news-\u002Fnews\u002Ftest-8":3},{"id":4,"title":5,"author":6,"authorPicture":7,"body":8,"category":49,"date":50,"description":51,"extension":52,"imageAlt":53,"imageUrl":54,"meta":55,"navigation":56,"path":57,"readingTime":58,"seo":59,"stem":60,"__hash__":61},"news\u002Fnews\u002Ftest-8.md","Lorem ipsum dolor sit amet","Dennis Postma","team-dennis.png",{"type":9,"value":10,"toc":43},"minimark",[11,15,20,23,36,40],[12,13,14],"p",{},"A broken DNSSEC chain does not degrade gracefully. Validating resolvers stop answering entirely, which means a mismatch between your DS record and your zone keys takes a domain offline for a large part of the internet.",[16,17,19],"h2",{"id":18},"continuous-validation","Continuous validation",[12,21,22],{},"DNSense now validates the chain of trust for every signed zone you manage and alerts you when something drifts.",[24,25,26,30,33],"ul",{},[27,28,29],"li",{},"DS record compared against the published keys",[27,31,32],{},"Warnings before signatures expire",[27,34,35],{},"Alerts by email, per space",[16,37,39],{"id":38},"during-a-provider-move","During a provider move",[12,41,42],{},"Key rollovers around a provider migration are the most common way to break signing. The zone overview now flags a signed zone before you move it, so the DS record is updated in the right order.",{"title":44,"searchDepth":45,"depth":45,"links":46},"",2,[47,48],{"id":18,"depth":45,"text":19},{"id":38,"depth":45,"text":39},"insights","2026-07-22","Lorem ipsum dolor sit amet, consectetur adipiscing elit. Aenean a molestie nisl, at vestibulum odio.","md","Photo of a screen with programming code","news-placeholder.png",{},true,"\u002Fnews\u002Ftest-8","10 minutes",{"title":5,"description":51},"news\u002Ftest-8","R1uB9EACK3MeBQjqDBStlfsEVb2crkD1mgz7vhUDldI",1785674142103]