DNSSEC requires extra planning when moving DNS hosting or transferring a cPanel account to another server.
cPanel's Zone Editor documentation instructs administrators to remove the domain's DS records from the registrar before transferring a DNSSEC-enabled domain, wait for that change to propagate, perform the transfer, and then publish the new DS records.
Why this matters
If the registrar continues publishing a DS record for an old signing key after the authoritative DNS has moved, validating resolvers can reject the new DNS responses.
For a planned DNSSEC migration, record the current state, schedule enough time for DS changes, and validate the domain after the new DS record is active.