Can you please fix security chain from top domain (.tv) to your subdomain plex.tv after all this years? I know issues with plex.tv and dnssec goes years back, it was part of a reason why i had to turn off dnssec validation on my resolver, but at least back then there where few others big domains with broken DNSSEC implementation, now you are pretty much on your own (you and sketchy ad domains). I opened logs this morning and this is 1hour snippet of broken dnssec implementation from my resolver:
27-Feb-2024 08:02:16.587 dnssec: info: validating app.plex.tv/A: no valid signature found
27-Feb-2024 08:02:16.587 dnssec: info: validating app.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:02:16.601 dnssec: info: validating plex.tv/SOA: no valid signature found
27-Feb-2024 08:02:16.601 dnssec: info: validating app.plex.tv/NSEC: no valid signature found
27-Feb-2024 08:02:18.057 dnssec: info: validating plex.tv/SOA: no valid signature found
27-Feb-2024 08:02:18.057 dnssec: info: validating clients.plex.tv/NSEC: no valid signature found
27-Feb-2024 08:02:18.057 dnssec: info: validating clients.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:02:18.057 dnssec: info: validating clients.plex.tv/A: no valid signature found
27-Feb-2024 08:02:18.251 dnssec: info: validating plex.tv/SOA: no valid signature found
27-Feb-2024 08:02:18.251 dnssec: info: validating plex.tv/NSEC: no valid signature found
27-Feb-2024 08:02:18.251 dnssec: info: validating plex.tv/A: no valid signature found
27-Feb-2024 08:02:18.824 dnssec: info: validating pubsub.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:02:18.824 dnssec: info: validating pubsub.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:02:18.824 dnssec: info: validating pubsub.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:02:18.941 dnssec: info: validating metadata.provider.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:02:18.941 dnssec: info: validating plex.tv/SOA: no valid signature found
27-Feb-2024 08:02:18.944 dnssec: info: validating metadata.provider.plex.tv/A: no valid signature found
27-Feb-2024 08:02:18.944 dnssec: info: validating discover.provider.plex.tv/NSEC: no valid signature found
27-Feb-2024 08:02:18.944 dnssec: info: validating discover.provider.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:02:18.944 dnssec: info: validating discover.provider.plex.tv/A: no valid signature found
27-Feb-2024 08:02:18.948 dnssec: info: validating plex.tv/SOA: no valid signature found
27-Feb-2024 08:02:18.948 dnssec: info: validating metadata.provider.plex.tv/NSEC: no valid signature found
27-Feb-2024 08:02:19.091 dnssec: info: validating assets.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:02:19.091 dnssec: info: validating assets.plex.tv/A: no valid signature found
27-Feb-2024 08:02:19.104 dnssec: info: validating together.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:02:19.104 dnssec: info: validating together.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:02:19.104 dnssec: info: validating together.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:02:21.391 dnssec: info: validating features.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:02:21.391 dnssec: info: validating features.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:02:21.401 dnssec: info: validating features.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:02:21.538 dnssec: info: validating community.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:02:21.538 dnssec: info: validating community.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:02:21.541 dnssec: info: validating community.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:02:21.741 dnssec: info: validating images.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:02:21.741 dnssec: info: validating plex.tv/SOA: no valid signature found
27-Feb-2024 08:02:21.741 dnssec: info: validating images.plex.tv/NSEC: no valid signature found
27-Feb-2024 08:02:21.748 dnssec: info: validating images.plex.tv/A: no valid signature found
27-Feb-2024 08:02:26.014 dnssec: info: validating metadata-static.plex.tv/A: no valid signature found
27-Feb-2024 08:02:26.031 dnssec: info: validating metadata-static.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:20:24.568 dnssec: info: validating v4.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:20:24.568 dnssec: info: validating v4.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:24:52.751 dnssec: info: validating plex.tv/A: no valid signature found
27-Feb-2024 08:24:52.985 dnssec: info: validating scrobbles.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:24:52.985 dnssec: info: validating scrobbles.plex.tv/A: no valid signature found
27-Feb-2024 08:40:48.095 dnssec: info: validating app.plex.tv/A: no valid signature found
27-Feb-2024 08:40:48.095 dnssec: info: validating plex.tv/SOA: no valid signature found
27-Feb-2024 08:40:48.095 dnssec: info: validating app.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:40:48.095 dnssec: info: validating app.plex.tv/NSEC: no valid signature found
27-Feb-2024 08:40:48.848 dnssec: info: validating clients.plex.tv/A: no valid signature found
27-Feb-2024 08:40:48.852 dnssec: info: validating plex.tv/SOA: no valid signature found
27-Feb-2024 08:40:48.852 dnssec: info: validating clients.plex.tv/NSEC: no valid signature found
27-Feb-2024 08:40:48.852 dnssec: info: validating clients.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:40:49.015 dnssec: info: validating plex.tv/A: no valid signature found
27-Feb-2024 08:40:49.015 dnssec: info: validating plex.tv/SOA: no valid signature found
27-Feb-2024 08:40:49.015 dnssec: info: validating plex.tv/NSEC: no valid signature found
27-Feb-2024 08:40:49.455 dnssec: info: validating pubsub.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:40:49.462 dnssec: info: validating pubsub.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:40:49.495 dnssec: info: validating pubsub.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:40:49.632 dnssec: info: validating together.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:40:49.635 dnssec: info: validating together.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:40:49.635 dnssec: info: validating together.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:40:49.689 dnssec: info: validating assets.plex.tv/A: no valid signature found
27-Feb-2024 08:40:49.689 dnssec: info: validating assets.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:40:49.692 dnssec: info: validating plex.tv/SOA: no valid signature found
27-Feb-2024 08:40:49.692 dnssec: info: validating discover.provider.plex.tv/NSEC: no valid signature found
27-Feb-2024 08:40:49.695 dnssec: info: validating discover.provider.plex.tv/A: no valid signature found
27-Feb-2024 08:40:49.695 dnssec: info: validating discover.provider.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:40:49.695 dnssec: info: validating metadata.provider.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:40:49.695 dnssec: info: validating plex.tv/SOA: no valid signature found
27-Feb-2024 08:40:49.695 dnssec: info: validating metadata.provider.plex.tv/A: no valid signature found
27-Feb-2024 08:40:49.695 dnssec: info: validating metadata.provider.plex.tv/NSEC: no valid signature found
27-Feb-2024 08:41:18.266 dnssec: info: validating features.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:41:18.279 dnssec: info: validating features.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:41:18.289 dnssec: info: validating features.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:41:18.563 dnssec: info: validating community.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:41:18.563 dnssec: info: validating community.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:41:18.563 dnssec: info: validating community.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:41:18.646 dnssec: info: validating vod.provider.plex.tv/A: no valid signature found
27-Feb-2024 08:41:18.646 dnssec: info: validating epg.provider.plex.tv/A: no valid signature found
27-Feb-2024 08:41:18.646 dnssec: info: validating plex.tv/SOA: no valid signature found
27-Feb-2024 08:41:18.646 dnssec: info: validating epg.provider.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:41:18.646 dnssec: info: validating epg.provider.plex.tv/NSEC: no valid signature found
27-Feb-2024 08:41:18.649 dnssec: info: validating vod.provider.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:41:18.649 dnssec: info: validating plex.tv/SOA: no valid signature found
27-Feb-2024 08:41:18.649 dnssec: info: validating vod.provider.plex.tv/NSEC: no valid signature found
27-Feb-2024 08:41:18.689 dnssec: info: validating images.plex.tv/A: no valid signature found
27-Feb-2024 08:41:18.693 dnssec: info: validating images.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:41:18.693 dnssec: info: validating plex.tv/SOA: no valid signature found
27-Feb-2024 08:41:18.693 dnssec: info: validating images.plex.tv/NSEC: no valid signature found
27-Feb-2024 08:41:34.690 dnssec: info: validating plex.tv/A: no valid signature found
27-Feb-2024 08:41:50.993 dnssec: info: validating clients.plex.tv/A: no valid signature found
27-Feb-2024 08:42:58.792 dnssec: info: validating plex.tv/A: no valid signature found
27-Feb-2024 08:44:08.270 dnssec: info: validating features.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:44:08.273 dnssec: info: validating features.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:44:08.287 dnssec: info: validating features.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:45:46.226 dnssec: info: validating app.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:45:46.226 dnssec: info: validating app.plex.tv/A: no valid signature found
27-Feb-2024 08:45:46.756 dnssec: info: validating clients.plex.tv/A: no valid signature found
27-Feb-2024 08:45:46.759 dnssec: info: validating clients.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:45:46.799 dnssec: info: validating plex.tv/A: no valid signature found
27-Feb-2024 08:45:47.313 dnssec: info: validating pubsub.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:45:47.483 dnssec: info: validating together.plex.tv/CNAME: no valid signature found
27-Feb-2024 08:45:47.526 dnssec: info: validating discover.provider.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:45:47.526 dnssec: info: validating discover.provider.plex.tv/A: no valid signature found
27-Feb-2024 08:45:47.533 dnssec: info: validating assets.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:45:47.536 dnssec: info: validating assets.plex.tv/A: no valid signature found
27-Feb-2024 08:45:50.103 dnssec: info: validating epg.provider.plex.tv/A: no valid signature found
27-Feb-2024 08:45:50.106 dnssec: info: validating metadata.provider.plex.tv/A: no valid signature found
27-Feb-2024 08:45:50.106 dnssec: info: validating vod.provider.plex.tv/A: no valid signature found
27-Feb-2024 08:45:50.113 dnssec: info: validating metadata.provider.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:54:52.770 dnssec: info: validating scrobbles.plex.tv/AAAA: no valid signature found
27-Feb-2024 08:54:52.770 dnssec: info: validating scrobbles.plex.tv/A: no valid signature found
27-Feb-2024 08:56:11.818 dnssec: info: validating cdn.adsquirrel.ai/A: no valid signature found
27-Feb-2024 08:56:15.042 dnssec: info: validating api.adsquirrel.ai/A: no valid signature found
27-Feb-2024 08:56:34.056 dnssec: info: validating media.adcanvas.com/A: no valid signature found
27-Feb-2024 08:56:34.542 dnssec: info: validating analytics.adcanvas.com/A: no valid signature found
this is dnsviz report for your domain: plex.tv | DNSViz
Now how to fix it. Its actually VERY easy:
according to this (and dnsviz):
; <<>> DiG 9.19.21 <<>> plex.tv DNSKEY +dnssec
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 23922
;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 1232
; COOKIE: 8b7a42f7ebc796240100000065dda729a75876044456c553 (good)
;; QUESTION SECTION:
;plex.tv. IN DNSKEY
;; ANSWER SECTION:
plex.tv. 615 IN DNSKEY 256 3 13 oJMRESz5E4gYzS/q6XDrvU1qMPYIjCWzJaOau8XNEZeqCYKD5ar0IRd8 KqXXFJkqmVfRvMGPmM1x8fGAa2XhSA==
plex.tv. 615 IN DNSKEY 257 3 13 mdsswUyr3DPW132mOi8V9xESWE8jTo0dxCjjnopKl+GqJxpVXckHAeF+ KkxLbxILfDLUT0rAK9iUzy1L53eKGQ==
plex.tv. 615 IN RRSIG DNSKEY 13 2 3600 20240427015641 20240226015641 2371 plex.tv. m1Qmqx5l3ZVuhkqktXupk2pHFQu+11gkzbXqUj0Pp8mxjs/q7Ilem3pF HZ49DeF86DDFKfpQ+BbMcuLI2BtpAw==
;; Query time: 0 msec
;; SERVER: 10.0.0.1#53(10.0.0.1) (UDP)
;; WHEN: Tue Feb 27 10:11:05 CET 2024
;; MSG SIZE rcvd: 327
your domain is using:
plex.tv. 615 IN DNSKEY 257 3 13 mdsswUyr3DPW132mOi8V9xESWE8jTo0dxCjjnopKl+GqJxpVXckHAeF+ KkxLbxILfDLUT0rAK9iUzy1L53eKGQ==
as a KSK (key signing key) with
key id: 2371
algorithm: ECDSA (or type 13)
digest type: SHA256 (or type 2)
digest: mdsswUyr3DPW132mOi8V9xESWE8jTo0dxCjjnopKl+GqJxpVXckHAeF+ KkxLbxILfDLUT0rAK9iUzy1L53eKGQ==
So you go to Godaddy and find dnssec and you add key there. Also check on cloudflare if you have some kind of KSK rollover enabled and turn it off, because otherwise when this happens you will need to manually update on GoDaddy… ZSK rollover is fine, since it happens only on nameserver and is managed by cloudflare, KSK rollover is not, since it needs manual intervention. This is generally how its done, i dont use godaddy or cloudflare, but its similar on all providers.
Thank you!