Loading…
Follows the chain of trust from the root servers down to the domain. At every zone cut the parent’s DS record is checked against the child’s DNSKEY by recomputing the digest — precisely what breaks when a KSK is rolled without updating the DS at the registrar.