Free tool

DNSSEC Checker

Test any domain's DNSSEC chain of trust — DS records at the registry, DNSKEY keys, signature expiry and live resolver validation.

Try:

What this checker looks at

DNSSEC works as a chain: the registry publishes a DS record that fingerprints your zone's key-signing key, your zone publishes DNSKEY records, and every answer carries an RRSIG signature. We fetch all three, confirm the DS key tag matches a published key, check signature expiry and algorithm strength, and ask a validating resolver whether the whole chain checks out.

Frequently asked questions

What is DNSSEC?
DNSSEC (DNS Security Extensions) adds cryptographic signatures to DNS records so resolvers can prove answers really came from the domain owner and weren't tampered with. It protects visitors from DNS spoofing and cache poisoning.
How do I enable DNSSEC?
Turn on DNSSEC signing at your DNS host (Cloudflare, Route 53, your registrar, etc.). It gives you a DS record — add that DS record at your domain registrar. Once both are in place, this checker should show Secure.
What does 'bogus' DNSSEC mean?
Bogus means the chain of trust is broken — usually a DS record at the registrar that no longer matches the zone's keys, often after switching DNS providers. Validating resolvers then refuse to answer, making the domain unreachable for many visitors.
Is DNSSEC required?
No. Most domains work fine without it, and an unsigned domain shows as Insecure here — that's a valid state. But a half-configured DNSSEC setup is worse than none, so if you enable it, make sure the result is Secure.

Need a better domain for your project?

Premium names, was $9,999 — now $1,000.

View domains