Domain: zentialia.tech (purchased through Vercel)
Plan: Hobby
Issue: Broken DNSSEC chain blocking all DNS verification
Problem Description
I purchased the domain zentialia.tech through Vercel about 3 weeks ago. For the past 2 days I have been trying to verify this domain in Google Workspace but the verification keeps failing — both via TXT record and CNAME record.
I ran a DNSViz analysis and it clearly shows a broken DNSSEC chain of trust
- There is a stale DS record in the
.techparent registry that points to DNSKEY id=28487, which no longer exists in Vercel’s nameservers. - This orphaned
DSrecord causes DNSSEC-validating resolvers to returnSERVFAILwhen querying any record forzentialia.tech. - As a result, Google cannot see my
TXTorCNAMEverification records, even though they are correctly added in the Vercel DNS dashboard.
Current vs Expected Behavior
- Current: Any DNS query to
zentialia.techreturnsSERVFAILon DNSSEC-validating resolvers. Google Workspace verification fails with “verification could not be completed.” - Expected: The
DSrecord in the.techregistry should match the activeDNSKEYin Vercel’s nameservers (or DNSSEC should be properly disabled), allowing DNS queries to resolve normally.
What I’ve Tried
- Added
TXTrecord:
google-site-verification=xDemDSSfK4bGaoKN4qb1pjdhEjPBQeEEWbqUOr42xJA
— already present for 2 days
2. Added CNAME record:
yab3sivjwj27 → gv-4cnvptudvenckp.dv.googlehosted.com
— already present
3. Both verification methods fail because of the underlying DNSSEC issue
4. The Vercel dashboard does not expose any option to manage or disable DNSSEC
What Needs to Be Done
- The orphaned DS record for
zentialia.techneeds to be removed from the.techregistry by whoever manages the registrar backend (Name.com / Vercel). This cannot be done by the user through the Vercel dashboard. - Could someone from the Vercel team please remove the stale
DSrecord forzentialia.techfrom the.techregistry? This would restore the DNSSEC chain of trust and allow Google Workspace verification to succeed.
Thank you!
tags:
<!DOCTYPE html><html data-beasties-container><head><meta charset="utf-8"><meta name="viewport" content="width=device-width, initial-scale=1"><title>Domain Names, Registration, Websites & Hosting | name.com</title>... (rest of HTML content) ...