Failing DNSSEC chain when reaching azurefd.net

Roy Freij 20 Reputation points
2025-12-12T14:28:56.1+00:00

Hello,

A fully trusted DNSSEC chain is required to successfully complete a Third-Party Audit.

Currently, when the DNSSEC chain is requested everything is fine, including the cname record, until it reaches azurefd.net.

These errors also appear when checking the domain directly: https://dnssec-debugger.verisignlabs.com/a01.azurefd.net

Are there any ways to resolve this issue?

Thank you in advance

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
0 comments No comments
{count} votes

Answer accepted by question author
  1. Vallepu Venkateswarlu 1,485 Reputation points Microsoft External Staff Moderator
    2025-12-12T14:47:44.53+00:00

    Hi @ Roy Freij •,

    Welcome to Microsoft Q&A Platform.

    Azure does not perform DNSSEC response validation using the default Azure-provided DNS resolver. DNSSEC validation is only relevant when you are running your own recursive DNS resolvers.

    Trust anchors and DNSSEC validation states:

    User's image

    In your scenario, the DNSSEC chain validates correctly until it reaches azurefd.net. This is because azurefd.net (Azure Front Door’s canonical domain) is not DNSSEC-signed

    Microsoft does not publish DS/RRSIG records for azurefd.net

    As a result, a fully trusted DNSSEC chain cannot be established when a CNAME ultimately points to Azure Front Door

    This is why external DNSSEC validation tools (such as Verisign DNSSEC Debugger) report failures for *.azurefd.net.

    Is there a way to resolve this?

    No. DNSSEC cannot be enabled for Microsoft-owned service domains like azurefd.net. Customers cannot configure DNSSEC on these zones.

    If a third-party audit requires full end-to-end DNSSEC validation, Azure Front Door cannot be used as the final CNAME target.

    Please Accept the answer if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.