# DELETE /api/v1/domains/{domain}/dnssec/{recordId}

> Attempt to remove one DS record

- Group: domains
- Tier: W
- Required scope: write:domains
- Docs: https://api.inleed.com/reference/domains/delete-dnssec-record

## Description

Returns `recordId`, `executed:false`, `supported:false`, `code`, a `note` and the resolved `target`. It removes nothing — no per-record delete exists.

## Path parameters

- `domain` — string (required)
- `recordId` — string (required)

## Query parameters

- `record_id` — string (required). Up to 64 characters. Pattern ^[A-Za-z0-9._-]+$.

## Request

```bash
curl -X DELETE "https://mcp.inleed.com/api/v1/domains/example.se/dnssec/rec_01hx8n3k5p7q9r2s4t6v8w0y13" \
  -H "Authorization: Bearer inl_live_…"
```

## Errors

- **400**  — codes: invalid_request
- **401** No token was presented, or the token is revoked, expired or unknown. — codes: unauthorized, token_expired, token_revoked
- **403** The token lacks a required scope, or this account does not own the resource. — codes: insufficient_scope, not_owned
- **404** No such resource for this account. — codes: not_found
- **422** Validation error — codes: validation_failed
- **429** The rate limit for this token is exhausted. See `Retry-After`. — codes: rate_limited
- **500** Something went wrong on our side. The failure is logged against `requestId`. — codes: internal_error

## Related

- GET /api/v1/domains/{domain}/dnssec — https://api.inleed.com/reference/domains/list-domain-dnssec
- POST /api/v1/domains/{domain}/dnssec — https://api.inleed.com/reference/domains/manage-dnssec
- GET /api/v1/domains — https://api.inleed.com/reference/domains/list-domains
- GET /api/v1/domains/{domain} — https://api.inleed.com/reference/domains/get-domain

