Sign up free

DNSSEC Checker – Test DNSSEC Validation for Any Domain

See whether a domain is signed with DNSSEC and whether validating resolvers accept it.

About DNSSEC Checker

DNSSEC signs DNS answers so resolvers can spot forged ones, but one broken link cuts a domain off from every validating resolver. Run the DNSSEC checker after you turn on signing at your DNS host, add a DS record at your registrar, move to another DNS provider or roll over keys. The DS and key checks run on the registrable domain, so www.example.com is checked under example.com. The WHOIS Lookup tells you which registrar holds the domain, if you need to find where the DS record goes.

The checker reads the DS records at the registry and the zone's DNSKEY records, labels each key as KSK or ZSK with its key tag, and checks that a DS record matches a published key. It asks validating resolvers whether answers carry the AD flag and spots bogus zones, which fail normally but resolve once validation is switched off with the CD flag. It also counts the days until the signatures expire, warns about RSA/SHA-1 algorithms and SHA-1-only DS digests, and lists the DS, DNSKEY and RRSIG records. For the domain's other records, use DNS Lookup.

How to use DNSSEC Checker

  1. 1
    Enter the domain

    Type the domain you want to test, for example example.com.

  2. 2
    Click Check

    We query the DS records at the registry, the zone's keys and a validating resolver.

  3. 3
    Read the verdict

    Each check passes or fails with a note on how to fix it, such as updating the DS record.

  4. 4
    Compare the records

    Match key tags across the DS, DNSKEY and signature tables, or download everything as JSON.

Why use Cubfile for this

  • Whole chain of trust

    DS at the registry and DNSKEY in the zone, matched by key tag.

  • Bogus zone detection

    Spots zones that fail validation, which cuts off users of validating resolvers.

  • Signature expiry

    Days left on the RRSIG signatures, with a warning shortly before they run out.

  • Algorithm review

    Warns about outdated RSA/SHA-1 keys and DS records that use only a SHA-1 digest.

FAQ

DNSSEC Checker: questions and answers

How do I know if DNSSEC is enabled for my domain?
Enter the domain. If the registry has no DS record and the zone has no DNSKEY, DNSSEC is off, which is still the case for most domains.
What does the AD flag mean?
Authenticated Data. A validating resolver sets it after checking the signatures all the way from the root, so it shows that DNSSEC works end to end.
My domain stopped resolving after I enabled DNSSEC. Why?
Usually the DS record at the registrar doesn't match the zone's key, often after a DNS provider move or a key change. The checker shows the key tags on both sides, so you can fix the DS record or remove it. After the fix, the DNS Propagation Checker shows when public resolvers answer again.
What's the difference between a KSK and a ZSK?
The key-signing key signs the zone's set of keys and is the one the DS record points to. The zone-signing key signs the other records, and some providers use a single key for both jobs.
Is the DNSSEC checker free?
Yes. It needs no account and doesn't use your daily tasks, with an hourly allowance per visitor to prevent abuse.
Share DNSSEC Checker with a friendIt runs in any browser, and they can try it without signing up.

Related tools

DNS DNS LookupLook up A, AAAA, CNAME, MX, NS, TXT, SOA, CAA and other DNS records.
WHOIS WHOIS LookupSee who registered a domain, when it was created and when it expires.
DNS DNS Propagation CheckerAsk a dozen public DNS resolvers at once to see whether a change has spread.
WHOIS Domain Availability CheckerCheck whether domains are still free to register, one or many at once.
DNS Subdomain FinderList a domain’s subdomains from public certificate transparency logs.
xnURL Punycode ConverterConvert Chinese and other international domain names to and from Punycode.
DNS Reverse DNS LookupFind the hostname behind an IP address from its PTR record.
SEO Broken Link CheckerCheck every link on a page and list the ones that are broken or redirected.