🛡️ DNSSEC Checker

Validate DNSSEC (Domain Name System Security Extensions) configuration to ensure proper DNS security implementation.

💡 Tip: Enter a domain and click "Check DNSSEC" to validate configuration.
Enter a domain and click "Check DNSSEC" to view results.

What the check looks at

The domain is queried live from our server, and the result highlights three things: whether the zone is signed, whether it publishes a DNSKEY, and whether answers come back with RRSIG signatures. Those are the pieces inside your zone. A working chain needs one more, held by the registry above you:

.             DNSKEY   root trust anchor, shipped with every resolver
com.          DS       hash of your key, published by the registry
example.com.  DNSKEY   your signing keys
              RRSIG    one signature per record set

Each level signs a hash of the level below. Break any link and a validating resolver stops trusting the answer.

The gap that catches everyone

This tells you what the zone publishes now. It cannot tell you the DS digest at your registrar still matches - after a key rollover, compare them by hand.

Frequently asked questions

How do I tell if DNSSEC is really validating?

Ask a validating resolver and look for the authenticated-data flag: dig @1.1.1.1 +dnssec example.com. An ad in the flags line means the whole chain checked out. Signatures present but no ad usually means the DS record is missing.

What happens to my site if DNSSEC breaks?

Names stop resolving for anyone behind a validating resolver - no page, no certificate warning, just a failure to look the domain up. Mail stops too, since sending servers resolve your MX records the same way.

Does DNSSEC replace HTTPS?

No. DNSSEC proves a DNS answer came from the real zone and was not altered on the way; it signs, it does not encrypt, and your queries stay readable. TLS still does the work of securing the connection afterwards.