Platform
ScaiWave ScaiGrid ScaiCore ScaiBot ScaiDrive ScaiKey Modellen Tools & Services
Oplossingen
Organisaties Ontwikkelaars Internet Service Providers Managed Service Providers AI-in-a-Box
Kenniscentrum
Ondersteuning Documentation Blog Downloads
Bedrijf
Over ons Onderzoek Vacatures Investeren Contact
Inloggen

Delegate a subzone securely (NS + DS)

Delegating a child zone (a subzone) means handing authority for part of your domain to another set of nameservers — for example e164.openenum.net served by a customer's own nameservers, while ScaiDNS keeps the parent openenum.net. To make that delegation DNSSEC-secure, the parent must also carry a DS record for the child so resolvers can extend the chain of trust across the cut.

A secure delegation is therefore two kinds of records in the parent zone, both at the child's name:

Record Purpose Who provides the value
NS Points queries for the child zone at its nameservers You (the child's NS hostnames)
DS Anchors DNSSEC trust to the child's key The child zone's operator (derived from their KSK)

Both record types are available in Add Record (the DS type is in the record type selector), and via the records API.

Steps#

  1. Add the NS delegation. In the parent zone (e.g. openenum.net), add an NS record named after the child (e164.openenum.net) for each of the child's nameservers.

  2. Get the DS from the child's operator. They produce it from the child zone's key-signing key (KSK). A DS value looks like:

    carbon
    1
    2
    <key-tag> <algorithm> <digest-type> <digest>
    2371 13 2 1f987cc6583e92df0890718c42…
    

    (algorithm e.g. 13 = ECDSA P-256; digest-type 2 = SHA-256.)

  3. Add the DS record(s). In the parent zone, add a DS record at the same name (e164.openenum.net) with that value. Add one DS record per digest they give you.

  4. Verify. Once published, resolvers can validate the child zone through the parent. You can confirm with dig +dnssec DS e164.openenum.net.

Removing a secure delegation#

Remove the DS record(s) first and allow them to expire from caches before the child stops signing, otherwise validating resolvers will treat the child as bogus. Remove the NS records when the delegation itself is withdrawn. (For a child ScaiDNS hosts under a ScaiDNS-hosted parent, disabling DNSSEC on the child withdraws the DS for you — see below.)

Child zones that ScaiDNS also hosts — automatic DS#

When the child zone is hosted in ScaiDNS and the parent is a ScaiDNS-hosted zone (an internal delegation, e.g. scaigit.scailabs.ai under scailabs.ai), you do not add the DS by hand. Just create the NS delegation (step 1); the DS is maintained for you:

  • Enabling DNSSEC on the child publishes its DS into the parent automatically (both SHA-256 and SHA-384 digests).
  • KSK rollover keeps the old and new DS in the parent together until the old key finishes retiring, so validation never breaks mid-rollover.
  • Disabling DNSSEC on the child removes the DS from the parent again.

This works even when the parent belongs to a different tenant, as long as ScaiDNS hosts it. If someone deletes a managed DS by hand, it is restored on the child's next key change. To turn this off and manage the DS manually (step 3 above), set the child domain's manage_parent_ds setting to false.

The manual DS steps above still apply when the parent is not hosted by ScaiDNS (a registrar or an external operator) — there is nowhere for ScaiDNS to write the DS, so you publish it at the registrar yourself. This is the e164.openenum.net case: the child runs on the customer's own nameservers, and its DS is added to the parent openenum.net via the UI or API as shown above.

Updated 2026-10-01 21:25:03 View source (.md) rev 3