DNSSEC checker

See whether a domain is signed: the DS records at the parent zone, the DNSKEY records in the zone itself, and whether two validating resolvers marked the answer as authenticated.

How DNSSEC is put together

DNSSEC adds signatures to DNS answers so that a resolver can verify they were not altered on the way. The zone publishes its public keys as DNSKEY records and signs its records with them. The parent zone (.com for example.com) publishes a DS record: a digest of the zone's key-signing key. That DS record is the link in the chain of trust from the root down to the domain, and it is set through the registrar.

Both halves are needed. Keys in the zone without a DS record at the parent are not validated by anyone. A DS record that points at a key the zone does not publish is worse: validating resolvers then refuse every answer and the domain disappears for their users.

What this tool checks and where the data comes from

OrbitProbe asks two public validating resolvers, Cloudflare and Google, over DNS-over-HTTPS for the DS and DNSKEY records of the registrable domain, with the DNSSEC OK bit set. It lists the DS records with key tag, algorithm and digest type, the DNSKEY records with their role (KSK or ZSK) and algorithm, and whether each resolver set the AD (Authenticated Data) flag on its answer. Where the registry publishes it, the RDAP "delegation signed" flag is shown as a second source.

The verdict is one of: signed (DS and DNSKEY present), not signed (the resolvers answered and there is no DS record), keys published without a DS record, DS present but keys unreadable, or could not be checked. If one resolver fails, the other one's answer is still used, and the failure is shown.

Reading the AD flag honestly

An AD flag means: these validating resolvers marked the answer authenticated at the time of the check. It is their statement about their own validation, not a certificate for the domain and not a promise about other resolvers. The tool does not re-verify signatures itself, and it does not walk every record of the zone, so an expired signature on a single record can go unnoticed here.

How to use this tool

  1. Enter the domain. Type or paste a domain name such as example.com. A full URL works too: the scheme, path and a leading www are removed.
  2. Query DS and DNSKEY. The tool asks two validating resolvers (Cloudflare and Google) over DNS-over-HTTPS, with the DNSSEC OK bit set.
  3. Read the verdict. See whether DS and DNSKEY records exist, which algorithms they use, and whether each resolver set the AD flag.

Command line equivalent

The same check from a terminal. The commands use example.com: replace it with your own name.

  • DS record at the parent zonedig +dnssec DS example.com
  • DNSKEY records of the zonedig +dnssec DNSKEY example.com +multi
  • AD flag from a validating resolverdig @1.1.1.1 example.com A +dnssec | grep flags
  • Same query over DNS-over-HTTPScurl -s -H "accept: application/dns-json" "https://cloudflare-dns.com/dns-query?name=example.com&type=DS&do=1"
  • Windows (PowerShell)Resolve-DnsName example.com -Type DNSKEY -DnssecOk

FAQ

How do I check whether a domain uses DNSSEC?

Enter the domain above, or run dig +dnssec DS example.com and dig +dnssec DNSKEY example.com. A signed domain has a DS record at the parent and DNSKEY records in the zone.

What is the difference between DS and DNSKEY?

DNSKEY records are the zone's public keys and live in the zone itself. The DS record is a digest of the key-signing key and lives in the parent zone, where it is set through the registrar.

Which algorithms are fine today?

ECDSAP256SHA256 (13), ED25519 (15) and RSASHA256 (8) are in common use. RSASHA1 variants (5 and 7) and SHA-1 DS digests (type 1) are deprecated and flagged by the tool.

The tool says not signed. Is that a problem?

Not by itself: many domains are unsigned and work. DNSSEC protects against forged DNS answers. Turning it on is a decision about operations, because a mistake in key rollover takes the domain offline for validating resolvers.

How do I turn DNSSEC off safely?

Remove the DS record at the registrar first, wait at least for its TTL to pass, and only then stop signing the zone. The other way round breaks resolution.