DNSSEC Check
Query DNSKEY, DS, and RRSIG records and validate chain of trust
Check a public domain for DNSKEY, DS, and RRSIG records, DNSSEC status, and chain-of-trust validation.
Public Internet targets only. Localhost, private IP ranges, link-local addresses, reserved networks, and metadata endpoints are blocked.
This checker queries DNSKEY, DS, and RRSIG records, detects DNSSEC status, and validates the chain of trust when possible.
DNSSEC Check Tester
Recent
What this DNSSEC Check validates
The DNSSEC checker queries DNSKEY, DS, and RRSIG records for a public domain, detects the DNSSEC status, and validates the chain of trust when enough DNSSEC data is available.
How to improve DNSSEC health
Publish matching DS records at the parent zone, keep DNSKEY records active at the authoritative zone, monitor RRSIG expiration, and confirm the domain validates from the root to the signed zone.
FAQ
What are DNSKEY, DS, and RRSIG records?
DNSKEY records publish DNSSEC public keys, DS records connect the parent zone to the signed child zone, and RRSIG records provide signatures that resolvers use to validate DNS answers.
Why does chain-of-trust validation matter?
The chain of trust confirms that DNSSEC records can be validated from the root zone through the parent zone to the domain being checked.