Muokkaa

Jaa


How to unsign your Azure Public DNS zone (Preview)

This article shows you how to remove Domain Name System Security Extensions (DNSSEC) from your Azure Public DNS zone.

To sign a zone with DNSSEC, see How to sign your Azure Public DNS zone with DNSSEC.

Note

DNSSEC zone signing is currently in PREVIEW.
See the Supplemental Terms of Use for Microsoft Azure Previews for legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
This DNSSEC preview is offered without a requirement to enroll in a preview. You can use Cloud Shell to sign or unsign a zone with Azure PowerShell or Azure CLI. Signing a zone by using the Azure portal is available in the next portal update.

Prerequisites

  • The DNS zone must be hosted by Azure Public DNS. For more information, see Manage DNS zones.
  • You must have permission to delete a DS record from the parent DNS zone. Most top level domains (.com, .net, .org) allow you to do this using your registrar.

Unsign a zone

Important

Removing DNSSEC from your DNS zone requires that you first remove the delegation signer (DS) record from the parent zone, and wait for the time-to-live (TTL) of the DS record to expire. After the DS record TTL has expired, you can safely unsign the zone.

To unsign a zone using the Azure portal:

  1. On the Azure portal Home page, search for and select DNS zones.

  2. Select your DNS zone, and then from the zone's Overview page, select DNSSEC. You can select DNSSEC from the menu at the top, or under DNS Management.

  3. If you have successfully removed the DS record at your registrar for this zone, you see that the DNSSEC status is Signed but not delegated. Do not proceed until you see this status.

    Screenshot of confirming to disable DNSSEC.

  4. Clear the Enable DNSSEC checkbox and select OK in the popup dialog box confirming that you wish to disable DNSSEC.

    Screenshot of DNSSEC status.

  5. In the Disable DNSSEC pane, type the name of your domain and then select Disable.

    Screenshot of the disable DNSSEC pane.

  6. The zone is now unsigned.

Next steps