Skip to content
FlexibleToolsAI
Security Toolkit · Free, Nothing Stored

DNSSEC Checker

See whether a domain's DNS answers are cryptographically signed and validated. The checker looks for DNSKEY records in the zone and a DS record at the parent, and asks a validating resolver whether the chain of trust verifies — catching half-configured and broken DNSSEC.

Enter a domain and we query it through Google Public DNS over HTTPS, reading the Authenticated Data (AD) flag plus the DNSKEY and DS records. You'll see one of: enabled and validating, signed but missing the DS record at the registrar, failing validation (SERVFAIL — which makes the domain unreachable), or not enabled.

Instant Results

Live checks in seconds

Nothing Stored

No logs of what you check

No Sign-Up

Free, no credits or email

Suggest a Feature or Improvement for DNSSEC Checker

Need custom options, higher limits, or extra format support? Let our engineering team know!

How to use DNSSEC Checker

  1. 1Enter the domain.
  2. 2Read the DNSSEC status.
  3. 3If it's signed but not delegated, add the DS record at your registrar.
  4. 4If validation fails, fix or roll back the keys urgently.

What DNSSEC protects against

Without DNSSEC, a resolver can be tricked into caching forged DNS answers (cache poisoning), sending visitors or email to an attacker. DNSSEC signs each record set, and validating resolvers reject answers whose signatures don't verify up the chain of trust to the root.

It needs two parts: your DNS host signs the zone (DNSKEY and RRSIG records) and your registrar publishes a DS record that links the parent zone to your key.

Enabling it safely

Most managed DNS providers (Cloudflare, Route 53, Google Cloud DNS) sign zones with one click and give you the DS record to add at the registrar. Broken DNSSEC is worse than none — a mismatched DS makes the domain fail to resolve — so re-check after changing DNS providers. See the rest of your setup with the Domain Security Checker.

Frequently Asked Questions

Does DNSSEC encrypt DNS?

No — it authenticates answers. Encryption of DNS queries is done by DNS-over-HTTPS or DNS-over-TLS.

What do you do with the domains and URLs I check?

Our server performs the lookup once and returns the result to your browser. We don't store the addresses you check or build a history. Private and internal addresses are blocked.

Is it free? Do I need an account?

It's completely free with no sign-up and no daily credits.

Related Tools