DNSSEC Checker

Walk the public trust chain and identify unsigned, partial, signed, or broken DNSSEC configuration.

Results will appear here.

What this check tells you

DNSSEC lets resolvers verify that DNS answers were signed by the authoritative zone. A DNSKEY without a parent DS is only partial; a parent DS without the matching zone keys can make a domain fail validation.

How to use the result

Queries use public DNS data. No account is required, and analytics never receives the domain you enter.