May we count visits with Google Analytics? It sets cookies and sends usage data to Google. Nothing loads unless you allow it. Cookie details
agents.staging.realtime.cloudflare.comObserved: Oct 11, 2026, 05:39 AM UTCPage: https://www.orbitprobe.com/dnssec-checker/agents.staging.realtime.cloudflare.com
DNSSEC check for agents.staging.realtime.cloudflare.com
Opens the print dialog of your browser. Choose "Save as PDF" as the printer there to get a file: the browser writes it, nothing is uploaded.
Share a snapshot of this report
A live report changes with every lookup, so a shared link to it would not show what you see now. A snapshot stores this report as our server observed it and gives it its own link for 30 days. It holds public lookup data only. Anyone with the link can open it; search engines are asked not to index it.
Result: Signed
Signed: a DS record exists at the parent zone and the zone publishes DNSKEY records.
DS records exist only at zone cuts, so the registrable domain cloudflare.com was checked.
AD flag from validating resolvers
Cloudflare (1.1.1.1)marked the answer authenticated (AD flag set)
Google Public DNS (8.8.8.8)marked the answer authenticated (AD flag set)
These validating resolvers marked the answer authenticated at the time shown. That is their statement about their own validation; OrbitProbe does not re-verify signatures.
DNSSEC adds signatures to DNS answers so that a resolver can verify they were not altered on the way. The zone publishes its public keys as DNSKEY records and signs its records with them. The parent zone (.com for example.com) publishes a DS record: a digest of the zone's key-signing key. That DS record is the link in the chain of trust from the root down to the domain, and it is set through the registrar.
Both halves are needed. Keys in the zone without a DS record at the parent are not validated by anyone. A DS record that points at a key the zone does not publish is worse: validating resolvers then refuse every answer and the domain disappears for their users.