---
title: Delegate a subzone securely (NS + DS)
path: tutorials/secure-delegation
status: published
---

# Delegate a subzone securely (NS + DS)

Delegating a child zone (a *subzone*) means handing authority for part of your
domain to another set of nameservers — for example `e164.openenum.net` served by
a customer's own nameservers, while ScaiDNS keeps the parent `openenum.net`. To
make that delegation **DNSSEC-secure**, the parent must also carry a **DS record**
for the child so resolvers can extend the chain of trust across the cut.

A secure delegation is therefore two kinds of records in the **parent** zone, both
at the child's name:

| Record | Purpose | Who provides the value |
|---|---|---|
| **NS** | Points queries for the child zone at its nameservers | You (the child's NS hostnames) |
| **DS** | Anchors DNSSEC trust to the child's key | The child zone's operator (derived from their KSK) |

Both record types are available in **Add Record** (the `DS` type is in the record
type selector), and via the records API.

## Steps

1. **Add the NS delegation.** In the parent zone (e.g. `openenum.net`), add an
   **NS** record named after the child (`e164.openenum.net`) for each of the
   child's nameservers.

2. **Get the DS from the child's operator.** They produce it from the child
   zone's key-signing key (KSK). A DS value looks like:

   ```
   <key-tag> <algorithm> <digest-type> <digest>
   2371 13 2 1f987cc6583e92df0890718c42…
   ```

   (`algorithm` e.g. `13` = ECDSA P-256; `digest-type` `2` = SHA-256.)

3. **Add the DS record(s).** In the parent zone, add a **DS** record at the same
   name (`e164.openenum.net`) with that value. Add one DS record per digest they
   give you.

4. **Verify.** Once published, resolvers can validate the child zone through the
   parent. You can confirm with `dig +dnssec DS e164.openenum.net`.

## Removing a secure delegation

Remove the **DS** record(s) first and allow them to expire from caches before the
child stops signing, otherwise validating resolvers will treat the child as bogus.
Remove the NS records when the delegation itself is withdrawn. (For a child ScaiDNS
hosts under a ScaiDNS-hosted parent, disabling DNSSEC on the child withdraws the DS
for you — see below.)

## Child zones that ScaiDNS also hosts — automatic DS

When the child zone is hosted in ScaiDNS **and** the parent is a ScaiDNS-hosted zone
(an internal delegation, e.g. `scaigit.scailabs.ai` under `scailabs.ai`), you do
**not** add the DS by hand. Just create the **NS** delegation (step 1); the DS is
maintained for you:

- **Enabling DNSSEC** on the child publishes its DS into the parent automatically
  (both SHA-256 and SHA-384 digests).
- **KSK rollover** keeps the old and new DS in the parent together until the old key
  finishes retiring, so validation never breaks mid-rollover.
- **Disabling DNSSEC** on the child removes the DS from the parent again.

This works even when the parent belongs to a **different tenant**, as long as ScaiDNS
hosts it. If someone deletes a managed DS by hand, it is restored on the child's next
key change. To turn this off and manage the DS manually (step 3 above), set the child
domain's `manage_parent_ds` setting to `false`.

The manual DS steps above still apply when the parent is **not** hosted by ScaiDNS
(a registrar or an external operator) — there is nowhere for ScaiDNS to write the DS,
so you publish it at the registrar yourself. This is the `e164.openenum.net` case:
the child runs on the customer's own nameservers, and its DS is added to the parent
`openenum.net` via the UI or API as shown above.
