DNSSEC Checker
Check whether a domain's DNSSEC configuration validates through independent public resolvers. Compare Cloudflare and Google, inspect DS and DNSKEY records, and distinguish secure, unsigned, partial and broken DNSSEC states.
DNSSEC analysis
Resolver evidence
AD flag and validated-vs-checking-disabled behavior from two public DNS-over-HTTPS resolvers.
DS records
Delegation Signer records visible through recursive DNS.
DNSKEY records
Public DNSSEC keys returned for the domain.
Findings and actions
Concrete evidence without a fabricated security score.
Methodology and limitations
What a DNSSEC checker should verify
Publishing DNSSEC records is not the same as passing end-to-end validation. The resolver verdict and the delegation chain both matter.
DNSSEC adds cryptographic signatures to DNS data so validating resolvers can detect tampering. A signed child zone publishes DNSKEY records, while the parent publishes a DS record that links the child into the DNSSEC chain of trust. If the chain is broken, validating resolvers can reject the response instead of silently accepting bad data.
AD flag
The Authenticated Data flag is set by a validating resolver when the returned data passed DNSSEC validation. This tool compares that signal from Cloudflare and Google.
DS record
The parent-side DS record identifies a DNSSEC key for the delegated child zone. Registrar-side DS data must stay synchronized with the keys actually published by the DNS provider.
DNSKEY record
DNSKEY records publish the public keys used by DNSSEC. Key material alone does not create an authenticated chain if the parent delegation does not contain the matching trust link.
Broken DNSSEC
If a validating resolver returns SERVFAIL but the same resolver can answer with checking disabled, the zone may be DNSSEC-bogus. This can make the domain unreachable for validating users.
Unsigned domain
An unsigned domain can resolve normally with AD=false. That is different from a broken signed zone: there is no failed validation chain to reject.
Resolver agreement
Comparing two independent validating resolvers helps separate a persistent DNSSEC state from a temporary cache or resolver-specific observation.
DNSSEC does not encrypt DNS queries
DNSSEC authenticates DNS data; it does not hide the domain being queried or encrypt the DNS transport. DNS-over-HTTPS and DNS-over-TLS address transport privacy, while DNSSEC addresses authenticity and integrity.
Why a broken DNSSEC setup can be worse than no DNSSEC
An unsigned domain can still resolve through ordinary DNS. A domain with a broken authenticated chain may instead return validation failures to security-aware resolvers. This commonly happens when a registrar DS record no longer matches the authoritative zone after an incorrect key rollover or DNS-provider migration.
How this checker determines the result
The tool queries Cloudflare and Google DNS-over-HTTPS with DNSSEC validation enabled and requests DNSSEC records. It also runs a comparison query with validation checking disabled. The resolver's AD flag is used as validation evidence. The tool does not claim to independently verify every cryptographic signature itself.
Related tools
Primary references
Google Public DNS JSON API · Cloudflare DNS-over-HTTPS JSON API