Checks

DNSSEC validation failed

A validating resolver rejected the DNSSEC chain.

Why it matters

Resolvers that validate will fail the lookup, so the name can disappear for those clients.

What to do

Fix the DS, DNSKEY, and signature records so the chain validates.

Reference

DNSSEC adds cryptographic authenticity to DNS responses.

ICANN — DNSSEC