Get hands-on experience with 20+ free Google Cloud products and $300 in free credit for new customers.

DNS propagation issue due to incorrect dnssec for cloud domain?

I have registered a cloud domain with google but since the beginning it had a problem with global propagation. Domain can be accessed only from some areas. I deduced that a possible reason for this is a problem with dnssec. I have never set any DS records so I'm not sure why there's an issue with it. I have tried disabling/enabling DNSSEC in Cloud Dns zone for my domain but it didn't change anything. Where can I report this issue? Officially domain registrar is not Google but Squarespace, yet when I log in to Squarespace I don't see my domain and there's no way to add it. In Google Cloud Dns I also don't have any way to clear dnssec records which seem already absent. I don't care if DNSSEC is on or off, my main concern is to make the domain resolve correctly.

fdfahueo313_2-1709175478883.png

 

fdfahueo313_0-1709175178799.png

fdfahueo313_0-1709177253034.png

 

Solved Solved
0 6 2,687
1 ACCEPTED SOLUTION

Hey @fdfahueo313 

Thanks for sharing the current configuration. Below I will try to explain how I would go about fixing this, assuming that you probably do no want to use DNSSec. Since your original configuration was with Cloud DNS as your DNS provider and it is a recommended setup, lets try configuring that again.

Go to your Cloud DNS zone (should you not have it anymore please re-create it). Click on the 'REGISTRAR SETUP' in the top right corner. Note the name servers responsible for your zone.

Under the Cloud Domains, change the DNS provider back to Cloud DNS and choose the zone.

Go to Google Domains and into the DNS configuration for your domain. Click on 'Custom name servers' near the top of the screen, click on manage name servers and populate name server with what you gathered in the last step (make sure only those four server from "Registrar setup" are configured here and nothing else), then click save. Make sure that DNSSec below is also disabled. If the notification at the top of the screen is yellow-ish and says 'your domain isn't using these settings', click on 'Switch to these settings', otherwise you should be done. After the changes propagate, you should be able to resolve records in Cloud DNS zone.

Alternatively, if you want to use Google Domains (which you probably don't) and choose to keep Google Domains as your DNS provider, you can try to just go to Google Domains and under the DNS configuration and Default name server create dns records under 'Custom records', similar to the one you have in Cloud DNS.

If that doesn't help, please share more of your configs - the content of your 'Registrar setup' in Cloud DNS, your 'default name server' configuration and 'custom name servers' configuration including which one is active in Google Domains and whatever else you think is relevant.

View solution in original post