Skip to content
Inspect My DNS

Delegation

DNSSEC signature expiry

delegation.dnssec-expiry

Signatures have a fixed validity window. A signer that stops re-signing — a forgotten cron job, a broken HSM, a migrated provider — takes the domain down for every validating resolver at the moment the last signature expires, with no warning before it.

What this check measures

Every DNSSEC signature (an RRSIG record) carries an inception and an expiration time, and a validating resolver rejects one outside that window exactly as it rejects a forged one. So a signed zone has to be re-signed continuously, and the moment the signer stops — a cron job nobody migrated, an HSM that failed, a provider change that left the old signer in charge — a countdown starts. Nothing visible happens until the last signature expires, and then the domain disappears for every validating resolver at once.

This check asks one of the domain's own nameservers directly, with recursion off and the DNSSEC OK bit set, for the signatures over the apex SOA and DNSKEY records, and reads when each runs out. It only runs for a zone with a DS record at the registry, because without one nothing validates the signatures and their expiry cannot take anything down. Where an RRset carries several signatures — normal during a key rollover — the one that lasts longest is the one that counts.

How much time is left is not on its own a warning sign. Signers that sign each answer as it is served (Cloudflare, NS1, Amazon Route 53 and others) use validity windows of a day or three, so their signatures are always days from expiry and always freshly made. The warning is reserved for the pattern a stalled signer produces: less than a quarter of the signature's own window left **and** less than a week, on a window longer than three days. A window that short is an online signer's, where a nearly-used-up signature can come from a short-lived cache, and a stalled one reaches outright expiry within hours anyway. An already-expired signature is a failure; it is usually also why the DNSSEC chain check above fails.

How to fix it

If the signatures have expired or are about to, re-sign the zone now — with most tools that is one command (dnssec-signzone, ldns-signzone, knotc zone-sign, pdnsutil rectify-zone followed by a reload) or one button at the DNS provider. The outage ends once fresh signatures are published and resolvers' cached failures time out.

Then find out why re-signing stopped. Check that the signing job is still scheduled and still succeeding, that the server holding the signing keys can reach them, and — after a provider migration — which provider is actually signing the zone the registry points at.

If you cannot restore signing quickly, the fallback is to unsign deliberately: remove the DS record at the registrar and wait for its TTL to pass before the signatures lapse. An unsigned domain resolves; a signed one with expired signatures does not.

Monitor it. Automated signers (BIND's dnssec-policy, Knot, PowerDNS, managed providers) handle re-signing for you, but they fail quietly; an alert on remaining signature validity is the only warning you will get.

References

Run this check on a domain

DNSSEC signature expiry is one of 62 checks in every report, alongside delegation, mail authentication, TLS and registration.