🛡️ DNSSEC Checker
Validate DNSSEC (Domain Name System Security Extensions) configuration to ensure proper DNS security implementation.
What the check looks at
The domain is queried live from our server, and the result highlights three things: whether the zone is signed, whether it publishes a DNSKEY, and whether answers come back with RRSIG signatures. Those are the pieces inside your zone. A working chain needs one more, held by the registry above you:
. DNSKEY root trust anchor, shipped with every resolver
com. DS hash of your key, published by the registry
example.com. DNSKEY your signing keys
RRSIG one signature per record set
Each level signs a hash of the level below. Break any link and a validating resolver stops trusting the answer.
The gap that catches everyone
- A signed zone with no DS record is not validated. Turning on signing at your DNS host is only half the job - the DS digest still has to be entered at your registrar, and registries can take a day to publish it.
- Failures are invisible to you. A broken signature returns SERVFAIL, not a warning page. Resolvers that validate, 1.1.1.1 and 8.8.8.8 among them, drop the domain entirely; everyone else sees a working site, which is why it reads as "some users only".
- Migrating DNS providers. Remove the DS record and wait for its TTL to pass before moving the zone, or the new provider's keys will not match what the parent still advertises.
Frequently asked questions
How do I tell if DNSSEC is really validating?
Ask a validating resolver and look for the authenticated-data flag:
dig @1.1.1.1 +dnssec example.com. An ad in the flags
line means the whole chain checked out. Signatures present but no
ad usually means the DS record is missing.
What happens to my site if DNSSEC breaks?
Names stop resolving for anyone behind a validating resolver - no page, no certificate warning, just a failure to look the domain up. Mail stops too, since sending servers resolve your MX records the same way.
Does DNSSEC replace HTTPS?
No. DNSSEC proves a DNS answer came from the real zone and was not altered on the way; it signs, it does not encrypt, and your queries stay readable. TLS still does the work of securing the connection afterwards.