Home/Website Tools/DNSSEC Checker
DNS security diagnostic

DNSSEC Checker

Check whether a domain's DNSSEC configuration validates through independent public resolvers. Compare Cloudflare and Google, inspect DS and DNSKEY records, and distinguish secure, unsigned, partial and broken DNSSEC states.

Cloudflare + GoogleDS + DNSKEYBroken-state detectionNo signup
DNSSEC explained

What a DNSSEC checker should verify

Publishing DNSSEC records is not the same as passing end-to-end validation. The resolver verdict and the delegation chain both matter.

DNSSEC adds cryptographic signatures to DNS data so validating resolvers can detect tampering. A signed child zone publishes DNSKEY records, while the parent publishes a DS record that links the child into the DNSSEC chain of trust. If the chain is broken, validating resolvers can reject the response instead of silently accepting bad data.

AD flag

The Authenticated Data flag is set by a validating resolver when the returned data passed DNSSEC validation. This tool compares that signal from Cloudflare and Google.

DS record

The parent-side DS record identifies a DNSSEC key for the delegated child zone. Registrar-side DS data must stay synchronized with the keys actually published by the DNS provider.

DNSKEY record

DNSKEY records publish the public keys used by DNSSEC. Key material alone does not create an authenticated chain if the parent delegation does not contain the matching trust link.

Broken DNSSEC

If a validating resolver returns SERVFAIL but the same resolver can answer with checking disabled, the zone may be DNSSEC-bogus. This can make the domain unreachable for validating users.

Unsigned domain

An unsigned domain can resolve normally with AD=false. That is different from a broken signed zone: there is no failed validation chain to reject.

Resolver agreement

Comparing two independent validating resolvers helps separate a persistent DNSSEC state from a temporary cache or resolver-specific observation.

DNSSEC does not encrypt DNS queries

DNSSEC authenticates DNS data; it does not hide the domain being queried or encrypt the DNS transport. DNS-over-HTTPS and DNS-over-TLS address transport privacy, while DNSSEC addresses authenticity and integrity.

Why a broken DNSSEC setup can be worse than no DNSSEC

An unsigned domain can still resolve through ordinary DNS. A domain with a broken authenticated chain may instead return validation failures to security-aware resolvers. This commonly happens when a registrar DS record no longer matches the authoritative zone after an incorrect key rollover or DNS-provider migration.

How this checker determines the result

The tool queries Cloudflare and Google DNS-over-HTTPS with DNSSEC validation enabled and requests DNSSEC records. It also runs a comparison query with validation checking disabled. The resolver's AD flag is used as validation evidence. The tool does not claim to independently verify every cryptographic signature itself.

Related tools

Primary references

Google Public DNS JSON API · Cloudflare DNS-over-HTTPS JSON API