Opens the print dialog of your browser. Choose "Save as PDF" as the printer there to get a file: the browser writes it, nothing is uploaded.
Share a snapshot of this report
A live report changes with every lookup, so a shared link to it would not show what you see now. A snapshot stores this report as our server observed it and gives it its own link for 30 days. It holds public lookup data only. Anyone with the link can open it; search engines are asked not to index it.
Result: Not signed
Not signed: the resolvers answered and there is no DS record at the parent zone.
AD flag from validating resolvers
Cloudflare (1.1.1.1)returned no DNSKEY records
Google Public DNS (8.8.8.8)returned no DNSKEY records
DS records at the parent zone
No DS records were returned.
DNSKEY records in the zone
No DNSKEY records were returned.
Registry (RDAP)
The registry reports the delegation as not signed.
LiveSource: DNS-over-HTTPS JSON: cloudflare-dns.com and dns.google (DO bit set); RDAP of the registryObserved:
How DNSSEC is put together
DNSSEC adds signatures to DNS answers so that a resolver can verify they were not altered on the way. The zone publishes its public keys as DNSKEY records and signs its records with them. The parent zone (.com for example.com) publishes a DS record: a digest of the zone's key-signing key. That DS record is the link in the chain of trust from the root down to the domain, and it is set through the registrar.
Both halves are needed. Keys in the zone without a DS record at the parent are not validated by anyone. A DS record that points at a key the zone does not publish is worse: validating resolvers then refuse every answer and the domain disappears for their users.