DNSSEC Checker
Walk the public trust chain and identify unsigned, partial, signed, or broken DNSSEC configuration.
Results will appear here.
What this check tells you
DNSSEC lets resolvers verify that DNS answers were signed by the authoritative zone. A DNSKEY without a parent DS is only partial; a parent DS without the matching zone keys can make a domain fail validation.
How to use the result
- Confirm the queried name is the exact hostname used by the affected service.
- Compare the returned values with the intended record in your authoritative DNS provider.
- Check TTL before changing records again; cached answers can outlive a rollback.
- Run the full domain report to correlate DNS with TLS, HTTP, routing, and provider incidents.
Queries use public DNS data. No account is required, and analytics never receives the domain you enter.