Plesk

Domain is not accessible from some locations after switching to Plesk nameservers due to DNSSEC misconfiguration

Symptoms

Cause

The issue is caused by the DNSSEC that was used on the external DNS side earlier. The domain contains a DS record in its zone. The DNS zone is signed on the external DNS side, not in Plesk:

# whois example.com | grep 'DNSSEC|Name'
Domain Name: EXAMPLE.COM
Name Server: ns1.externalnameserver.com
Name Server: ns2.externalnameserver.com
DNSSEC: signedDelegation
DNSSEC DS Data: 2371 8 2 05018AD82430B60DC43FC0816C98797BC62EB67E57AA98AABC82D7ACD5A8CBC1

Resolution

Apply one of the solutions below:

To completely disable DNSSEC

Remove the DS record from the parent zone on the external DNS side, for example, using the domain registrar's panel.

To fix DNSSEC

  1. Remove old DS records from the parent zone on the external DNS side.
  2. Log into Plesk.
  3. Install the DNSSEC extension.
  4. Configure DNSSEC for the domain using the following guide.