DNSSEC Checker
See whether a domain's DNS answers are cryptographically signed and validated. The checker looks for DNSKEY records in the zone and a DS record at the parent, and asks a validating resolver whether the chain of trust verifies — catching half-configured and broken DNSSEC.
Enter a domain and we query it through Google Public DNS over HTTPS, reading the Authenticated Data (AD) flag plus the DNSKEY and DS records. You'll see one of: enabled and validating, signed but missing the DS record at the registrar, failing validation (SERVFAIL — which makes the domain unreachable), or not enabled.
Instant Results
Live checks in seconds
Nothing Stored
No logs of what you check
No Sign-Up
Free, no credits or email
Suggest a Feature or Improvement for DNSSEC Checker
Need custom options, higher limits, or extra format support? Let our engineering team know!
How to use DNSSEC Checker
- 1Enter the domain.
- 2Read the DNSSEC status.
- 3If it's signed but not delegated, add the DS record at your registrar.
- 4If validation fails, fix or roll back the keys urgently.
What DNSSEC protects against
Without DNSSEC, a resolver can be tricked into caching forged DNS answers (cache poisoning), sending visitors or email to an attacker. DNSSEC signs each record set, and validating resolvers reject answers whose signatures don't verify up the chain of trust to the root.
It needs two parts: your DNS host signs the zone (DNSKEY and RRSIG records) and your registrar publishes a DS record that links the parent zone to your key.
Enabling it safely
Most managed DNS providers (Cloudflare, Route 53, Google Cloud DNS) sign zones with one click and give you the DS record to add at the registrar. Broken DNSSEC is worse than none — a mismatched DS makes the domain fail to resolve — so re-check after changing DNS providers. See the rest of your setup with the Domain Security Checker.
Frequently Asked Questions
Does DNSSEC encrypt DNS?
No — it authenticates answers. Encryption of DNS queries is done by DNS-over-HTTPS or DNS-over-TLS.
What do you do with the domains and URLs I check?
Our server performs the lookup once and returns the result to your browser. We don't store the addresses you check or build a history. Private and internal addresses are blocked.
Is it free? Do I need an account?
It's completely free with no sign-up and no daily credits.
Related Tools
Domain Security Checker
Scan a domain's email, DNS and HTTPS security: SPF, DMARC, DNSSEC, CAA, SSL, HSTS and headers.
SPF Record Checker
Validate a domain's SPF record, count DNS lookups against the limit of 10, and see the include tree.
SSL Checker
Check a site's SSL/TLS certificate, chain, expiry, TLS versions, HTTPS redirect and HSTS.