Configure DNS before submitting nameservers
The .it Registry checks the proposed nameservers and zone. A domain can remain inactive or a nameserver update can remain pending if the authoritative DNS configuration does not pass validation.
Core requirements
What the DNS must provide
- Provide between two and six reachable nameservers.
- Every listed server must be authoritative for the exact domain.
- The zone must contain a valid SOA record and consistent NS records.
- Nameserver hostnames and their IP addresses must resolve correctly.
- The nameservers must answer reliably without NXDOMAIN, SERVFAIL or timeout responses for the zone.
Website and email records
Add the records the domain will use
Configure the root domain and any required www, mail and MX records before changing delegation. The Registry validates DNS structure; it does not build the website or mailbox configuration for you.
- Website
- A or AAAA record for the root domain
- Web alias
- Usually an A record or CNAME for www
- MX record plus a resolvable mail host
- Authority
- Matching SOA and NS records
Common reasons validation fails
The zone exists on only one nameserver, NS records differ between servers, the SOA primary server is incorrect, a server is blocked by a firewall, or the submitted hostname resolves to the wrong IP address.
Before submitting
Use the official DNS validator
- Open Registro.it DNS Verify.
- Enter the .it domain name.
- If the domain is not registered or the new servers differ from its current delegation, enter the proposed nameservers.
- Run the validation and correct every failed check before submitting the nameserver change.
DNSSEC
Validate DS records when DNSSEC is enabled
If you intend to use DNSSEC, include the proposed DS record in the Registry validator. A stale or incorrect DS record can make an otherwise correct domain fail to resolve.
Need UKC to check the zone?
Send the .it domain and all proposed nameserver hostnames. Include the validator's failed test names, but never send server passwords.
Ask the Helpdesk