EML

DNSSEC Checker

See whether a domain's DNS answers are signed and verifiable, whether the DS record at the registrar matches the zone's keys, and whether validation is failing.

Queries go straight from your browser to the resolver you pick.

How it works

DNSSEC builds a chain of trust. The root zone vouches for each top-level domain, the top-level domain vouches for your domain by publishing a DS record, and your zone signs its own records with the keys the DS record points to. A validating resolver walks that chain and only returns an answer, marked authenticated, if every link checks out.

This tool asks the resolver you pick for your DS records, your DNSKEY records and an authenticated lookup. It computes each key's tag to confirm the DS record really matches a key in your zone, reviews the algorithms and key sizes, and detects a broken setup by repeating a failed lookup with validation switched off.

ResultMeaning
ValidDS and DNSKEY match and the resolver verified the whole chain.
IncompleteKeys are published but the parent has no DS yet, so DNSSEC is not active.
BrokenA DS exists but does not match or validation fails. Validating resolvers cannot reach the domain.
InheritedNo keys of its own; covered by a signed parent zone.
Not enabledNo DNSSEC. Optional.

For the raw records use the DNS Lookup Tool, and after a change to your nameservers see how far it has spread with the DNS Propagation Checker.

Frequently asked

What does DNSSEC do?

DNSSEC adds digital signatures to DNS answers so that a resolver can prove an answer really came from the domain's owner and was not forged or altered on the way. It protects against DNS spoofing and cache poisoning. It does not encrypt anything.

Do I need DNSSEC?

It is optional. It is worth enabling for domains that handle sensitive traffic or email, and many registries and security guides recommend it. It also adds upkeep: if keys or DS records get out of step, validating resolvers stop resolving your domain.

What are DS and DNSKEY records?

The DNSKEY records live in your own zone and hold the public keys used to verify your signatures. The DS record is a fingerprint of your key-signing key, stored at the parent (the registry, through your registrar). The DS is what links your zone into the chain of trust.

Why does the tool say DNSSEC is broken when my site loads for me?

Some resolvers do not validate DNSSEC, and a browser on such a network will load the site anyway. People behind validating resolvers, including Cloudflare, Google and Quad9 and many ISPs, will get an error. The tool detects this by seeing a failure that disappears when validation is turned off.

How do I turn DNSSEC off safely?

Remove the DS record at your registrar first and wait for the old DS time-to-live to expire (often a day or two) before you disable signing at your DNS provider. Doing it in the other order leaves a DS pointing at keys that no longer exist, which breaks resolution.

Why does a subdomain show no keys?

DNSSEC is set up once per zone, normally at the registered domain. A subdomain without its own keys is covered by the signed parent zone, and the tool reports that as inherited when the resolver validates it.