Post-Quantum DNSSEC Check

Classify DNSSEC algorithms and test DNSKEY over UDP and TCP

Check a public domain for DNSSEC algorithm classification, ML-DSA signals, and DNSKEY behavior over UDP and TCP.

Public Internet targets only. Localhost, private IP ranges, link-local addresses, reserved networks, and metadata endpoints are blocked.

This checker classifies DNSSEC algorithms, detects ML-DSA when present, and measures DNSKEY response behavior over UDP and TCP.

Post-Quantum DNSSEC Check Tester

Port.Tools and more available on mobile:

What this Post-Quantum DNSSEC Check tests

The post-quantum DNSSEC checker classifies DNSSEC algorithms, looks for ML-DSA signals, and measures DNSKEY behavior over UDP and TCP so you can review DNSSEC readiness beyond traditional signatures.

How to improve post-quantum DNSSEC readiness

Track DNSSEC algorithm support from your registry, DNS provider, and resolvers, test large DNSKEY responses over both UDP and TCP, and watch for ML-DSA adoption as post-quantum DNSSEC deployments mature.

FAQ

What is ML-DSA in DNSSEC?

ML-DSA is a post-quantum digital signature algorithm. In DNSSEC, ML-DSA adoption is still emerging, so this checker focuses on algorithm classification and DNSKEY transport behavior.

Why test DNSKEY over UDP and TCP?

Post-quantum DNSSEC signatures and keys can increase response sizes. Testing UDP and TCP behavior helps reveal truncation, fallback, and resolver transport issues.