About DNSSEC Checker
DNSSEC signs DNS answers so resolvers can spot forged ones, but one broken link cuts a domain off from every validating resolver. Run the DNSSEC checker after you turn on signing at your DNS host, add a DS record at your registrar, move to another DNS provider or roll over keys. The DS and key checks run on the registrable domain, so www.example.com is checked under example.com. The WHOIS Lookup tells you which registrar holds the domain, if you need to find where the DS record goes.
The checker reads the DS records at the registry and the zone's DNSKEY records, labels each key as KSK or ZSK with its key tag, and checks that a DS record matches a published key. It asks validating resolvers whether answers carry the AD flag and spots bogus zones, which fail normally but resolve once validation is switched off with the CD flag. It also counts the days until the signatures expire, warns about RSA/SHA-1 algorithms and SHA-1-only DS digests, and lists the DS, DNSKEY and RRSIG records. For the domain's other records, use DNS Lookup.
How to use DNSSEC Checker
- 1Enter the domain
Type the domain you want to test, for example example.com.
- 2Click Check
We query the DS records at the registry, the zone's keys and a validating resolver.
- 3Read the verdict
Each check passes or fails with a note on how to fix it, such as updating the DS record.
- 4Compare the records
Match key tags across the DS, DNSKEY and signature tables, or download everything as JSON.
Why use Cubfile for this
- Whole chain of trust
DS at the registry and DNSKEY in the zone, matched by key tag.
- Bogus zone detection
Spots zones that fail validation, which cuts off users of validating resolvers.
- Signature expiry
Days left on the RRSIG signatures, with a warning shortly before they run out.
- Algorithm review
Warns about outdated RSA/SHA-1 keys and DS records that use only a SHA-1 digest.