• Home
  • Archive
  • Tools
  • Contact Us

The Customize Windows

Technology Journal

  • Cloud Computing
  • Computer
  • Digital Photography
  • Windows 7
  • Archive
  • Cloud Computing
  • Virtualization
  • Computer and Internet
  • Digital Photography
  • Android
  • Sysadmin
  • Electronics
  • Big Data
  • Virtualization
  • Downloads
  • Web Development
  • Apple
  • Android
Advertisement
You are here:Home » How to Migrate Name Servers with DNSSEC Record

By Abhishek Ghosh October 4, 2021 6:58 pm Updated on October 4, 2021

How to Migrate Name Servers with DNSSEC Record

Advertisement

You may need to migrate your DNS hosting from one provider to another DNS provider for different reasons and when you have activated DNSSEC Record, then the job is slightly difficult but potential downtime can be avoided if the steps are done correctly. DNSSEC Record is great since no party can run a man-in-the-middle exploit.

As for real-life examples, we use Tucows/Hover as domain registrar for this website and Rage4 DNS as DNS provider. If we want to suddenly move our DNS hosting from Rage4 to DNSMadeEasy, then it is not easy. Because the DNSSEC is designed to stop this kind of “quick hijacking”. There are many reasons behind planning to move DNS hosting from one provider to another DNS provider, one of the dreaded is loss of access to the account. Loss of access to your DNS account may happen out of technical issues of the provider. For the above-given scenario, you can move your DNS provider with 24-48 hours downtime. But, you may completely avoid downtime if you start the process early and plan fully.

 

Step 1 : Check the Records and Backup All the DNS Records

 

If you have a backup of all the DNS records then it will be easy to migrate. Create an account at your planned DNS hosting provider’s website. Copy-paste all the records except the DNSSEC record. Do not publish the records. You’ll not add any new DNSSEC record here, in the new account.

Advertisement

---

We can check the DNSSEC record of our domain using Dig :

Vim
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
dig ds thecustomizewindows.com
 
; <<>> DiG 9.10.3-P4-Ubuntu <<>> ds thecustomizewindows.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 50775
;; flags: qr rd ra ad; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1
 
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;thecustomizewindows.com.       IN      DS
 
;; ANSWER SECTION:
thecustomizewindows.com. 86400  IN      DS      45657 10 1 0B42DF107AFF729E6520DAE85CAFB712C0FA3A21
thecustomizewindows.com. 86400  IN      DS      45657 10 2 4ECEF3F41FE0A18EE5FC018EF5DE79587C243215463011D8A7BEBEAC 5CF84FFD
thecustomizewindows.com. 86400  IN      DS      45657 10 4 B8AF03E972B7DE22D610DC40FAF0228DEA131B83CF224E797FB47661 831BEA3034EC3CDD0290DFAE30FF24B03E13B718
 
;; Query time: 87 msec
;; SERVER: 1.1.1.1#53(1.1.1.1)
;; WHEN: Sun Oct 03 22:32:46 IST 2021
;; MSG SIZE  rcvd: 200

And also by using this excellent DNSSEC analysis tool by Verisign.

How to Migrate Name Servers with DNSSEC Record

 

Step 2 : Delete the DNSSEC Record from Domain Registrar

 

Login to the website of your domain registrar, for example, Tucows/Hover in our case. Any standard registrar will have this kind of help page for their DNSSEC service:

Vim
1
https://help.hover.com/hc/en-us/articles/217281647-DNSSEC-services

Take a screenshot and proceed to delete the records. This process will erase the declaration of authority from the domain registrar. After 24 hours, check the DNSSEC record using Verisign’s tool and Dig. You have to wait till the whole internet forgets the declaration from the domain registrar’s side.

 

Step 3 : Delete the DNSSEC Record from Old DNS Host

 

You have kept the new account of the DNS host ready. You need to delete the DNSSEC record associated with the record in the (old) DNS host’s list at least 24 hours before publishing the records from the new account. Now, in case you have lost access, at least for the paid DNS services, no-host will forever host your records for free. If the host can not return your account, they will help to erase the records. At that moment you have to change the nameservers from the domain registrar and publish the new set of DNS records from a new account.

 

Conclusion

 

By early turning off the DNSSEC record at the registrar’s website, you are breaking the “trust chain”. Within 48 hours, the DNSSEC record created at DNS host losing its merit. You should re-enable DNSSEC after a week or so when you are sure that the migration has been completed.

Facebook Twitter Pinterest

Abhishek Ghosh

About Abhishek Ghosh

Abhishek Ghosh is a Businessman, Surgeon, Author and Blogger. You can keep touch with him on Twitter - @AbhishekCTRL.

Here’s what we’ve got for you which might like :

Articles Related to How to Migrate Name Servers with DNSSEC Record

  • Nginx WordPress Installation Guide (All Steps)

    This is a Full Nginx WordPress Installation Guide With All the Steps, Including Some Optimization and Setup Which is Compatible With WordPress DOT ORG Example Settings For Nginx.

  • How to Change DNS Provider for Domains with DNSSEC Active

    DNSSEC is a great security feature for the domains. Previously we published guides on how to enable DNSSEC and DANE TLSA record. Take that, you use Hover as your domain registrar and DNSMadeEasy as your DNS provider. Now you want to move to CloudFlare from DNSMadeEasy. If you suddenly change the DNS with the DNSSEC […]

  • WordPress & PHP : Different AdSense Units on Mobile Devices

    Here is How To Serve Different AdSense Units on Mobile Devices on WordPress With PHP. WordPress Has Function Which Can Be Used In Free Way.

  • How to Enable DNSSEC With Dyn For Higher Security

    DNS Security Extensions (DNSSEC) Secures the Infrastructure. Here is How to Enable DNSSEC With Dyn & Domain Register For Higher Security.

performing a search on this website can help you. Also, we have YouTube Videos.

Take The Conversation Further ...

We'd love to know your thoughts on this article.
Meet the Author over on Twitter to join the conversation right now!

If you want to Advertise on our Article or want a Sponsored Article, you are invited to Contact us.

Contact Us

Subscribe To Our Free Newsletter

Get new posts by email:

Please Confirm the Subscription When Approval Email Will Arrive in Your Email Inbox as Second Step.

Search this website…

 

Popular Articles

Our Homepage is best place to find popular articles!

Here Are Some Good to Read Articles :

  • Cloud Computing Service Models
  • What is Cloud Computing?
  • Cloud Computing and Social Networks in Mobile Space
  • ARM Processor Architecture
  • What Camera Mode to Choose
  • Indispensable MySQL queries for custom fields in WordPress
  • Windows 7 Speech Recognition Scripting Related Tutorials

Social Networks

  • Pinterest (24.3K Followers)
  • Twitter (5.8k Followers)
  • Facebook (5.7k Followers)
  • LinkedIn (3.7k Followers)
  • YouTube (1.3k Followers)
  • GitHub (Repository)
  • GitHub (Gists)
Looking to publish sponsored article on our website?

Contact us

Recent Posts

  • Hybrid Multi-Cloud Environments Are Becoming UbiquitousJuly 12, 2023
  • Data Protection on the InternetJuly 12, 2023
  • Basics of BJT TransistorJuly 11, 2023
  • What is Confidential Computing?July 11, 2023
  • How a MOSFET WorksJuly 10, 2023
PC users can consult Corrine Chorney for Security.

Want to know more about us?

Read Notability and Mentions & Our Setup.

Copyright © 2023 - The Customize Windows | dESIGNed by The Customize Windows

Copyright  · Privacy Policy  · Advertising Policy  · Terms of Service  · Refund Policy