[public-dns-discuss] Re: DNS Configuration

There are a bunch of problems with your configuration, http://dnsviz.net/d/cpss.co/XDyj7A/dnssec/ shows some of them.

While it is possible to DNSSEC-sign your domains separately with different keys on each name server, this is not generally advised (and for proper functionality, requires that the two name servers cross-sign each others DNSKEY RRsets).

You should do the DNSSEC-signing on one name server, set it up as a primary, and the other as a secondary which will transfer the zones. Once that is set up, you can register the DS record for your domain's KSK (key-signing DNSKEY, the one with 257, not 256) with eNom and you should have a working DNSSEC configuration.

