Skip to content
Aback Tools Logo

DNSSEC Checker

Check whether any domain has DNSSEC enabled with our free online DNSSEC checker. Query DS, DNSKEY, and RRSIG records via Cloudflare's DNS-over-HTTPS API. View cryptographic algorithm types, key roles (KSK/ZSK), AD flag status, and signature timestamps - all from your browser with no data stored on our servers.

DNSSEC Checker

Check whether a domain has DNSSEC enabled. Queries DS, DNSKEY, and RRSIG records via Cloudflare's DNS-over-HTTPS (DoH) API and shows the AD (Authenticated Data) flag. No data is stored - all queries go directly from your browser to the DNS resolver.

Enter a domain name - protocol and path are stripped automatically

Quick check:

Why Use Our DNSSEC Checker?

Instant DNSSEC Validation Check

Our DNSSEC checker queries DS, DNSKEY, and RRSIG records instantly via Cloudflare's DNS-over-HTTPS API. Check if any domain has DNSSEC enabled in seconds with detailed cryptographic record information - no installation required.

Detailed Cryptographic Record Analysis

View complete DNSSEC details including DS record key tags and digest types, DNSKEY algorithm names and key roles (KSK/ZSK), and RRSIG signatures with inception and expiration timestamps. Understand the full DNSSEC chain for any domain.

Secure & Private DNS-over-HTTPS

All DNSSEC queries are sent directly from your browser to Cloudflare's DNS-over-HTTPS endpoint over an encrypted HTTPS connection. No query data is stored on our servers - your DNSSEC checks are completely private.

Free & No Installation Required

Use our free DNSSEC checker directly in your browser with no downloads, no plugins, and no account required. Check DNSSEC status for any domain from any device, anytime - completely free with no usage limits.

Common Use Cases for DNSSEC Checker

Domain Security Verification

Security-conscious domain owners use the DNSSEC checker to verify that DNSSEC is properly configured for their domains. Regular checks ensure that the cryptographic chain of trust is intact and that DNS records are protected against spoofing and cache poisoning attacks.

DevOps & Infrastructure Auditing

DevOps engineers use the DNSSEC checker to audit DNS configurations during infrastructure setup and migrations. Verify that DNSSEC is correctly configured after domain transfers, registrar changes, or DNS provider switches.

DNS Spoofing Protection Assessment

Security researchers and network administrators use the DNSSEC checker to assess which domains in their organisation are protected against DNS spoofing. Identify domains that lack DNSSEC protection and prioritise remediation efforts.

DNS Health Monitoring

Network administrators use the DNSSEC checker as part of ongoing DNS health monitoring. Check that DNSSEC signatures are valid and have not expired, and that DS records in the parent zone match the domain's DNSKEY records.

Security Research & Threat Intelligence

Security researchers use the DNSSEC checker to investigate DNS configurations of suspicious domains. DNSSEC status can indicate how security-conscious a domain operator is and help assess the trustworthiness of unknown domains.

Compliance & Regulatory Auditing

Compliance officers and auditors use the DNSSEC checker to verify that domains meet DNSSEC requirements mandated by security frameworks such as PCI DSS, NIST, and BSI. Generate check results for compliance documentation.

Understanding DNSSEC

What is DNSSEC?

DNSSEC (Domain Name System Security Extensions) is a suite of specifications that add cryptographic signatures to DNS records. These signatures allow DNS resolvers to verify that the records they receive have not been tampered with in transit. Without DNSSEC, DNS responses can be forged by attackers through techniques like DNS spoofing and cache poisoning, redirecting users to malicious websites even when they type the correct domain name. Our DNSSEC checker queries DNS records via DNS-over-HTTPSusing Cloudflare's public resolver to check DNSSEC status for any domain.

How Our DNSSEC Checker Works

  1. Enter a Domain Name: Type any domain name into the input field (e.g. example.com). The tool automatically strips protocols and paths.
  2. Query DNSSEC Records:The tool queries three types of DNSSEC records from Cloudflare's DoH resolver - DS (Delegation Signer) records from the parent zone, DNSKEY records from the domain itself, and RRSIG (Resource Record Signature) records. It also checks the AD (Authenticated Data) flag in the DNS response header.
  3. Review Results: The DNSSEC checker displays a clear pass/fail status, detailed record tables showing cryptographic parameters (key tags, algorithms, digest types), key roles (KSK/KSR/ZSK), and signature timestamps. Copy any value with one click.

DNSSEC Record Types Explained

  • DS (Delegation Signer):Stored in the parent zone (e.g., .com for example.com). Contains a hash of the child zone's DNSKEY record. DS records are how the chain of trust is established - the parent signs the DS record, and resolvers use it to verify the child's DNSKEY. Without a DS record, a domain cannot have full DNSSEC validation.
  • DNSKEY: Contains the public key used by the zone to sign its DNS records. Two types exist: KSK (Key Signing Key, flag 257) used to sign other DNSKEY records, and ZSK (Zone Signing Key, flag 256) used to sign all other records in the zone. The KSK is what the DS record in the parent zone authenticates.
  • RRSIG (Resource Record Signature):The digital signature attached to each DNS record set. Each RRSIG record specifies which algorithm was used, when the signature was created, when it expires, which key signed it, and the signature value itself. Resolvers verify RRSIG records against the zone's DNSKEY to authenticate each DNS response.

Algorithm Types and Security

DNSSEC supports multiple cryptographic algorithms for signing DNS records. Common algorithms include RSA/SHA-256 (algorithm 7, widely supported),RSA/SHA-512 (algorithm 8, stronger), ECDSA P-256 (algorithm 13, modern elliptic curve), and Ed25519 (algorithm 15, efficient and modern). The digest type in DS records indicates the hash function used - SHA-256 (type 2) is the current standard, while SHA-1 (type 1) is being phased out due to collision vulnerabilities. Modern best practice uses algorithm 13 (ECDSA P-256) or 15 (Ed25519) with SHA-256 digests for optimal security and performance. Our DNSSEC checker displays all these values so you can verify that a domain uses current, secure cryptographic parameters.

Frequently Asked Questions About DNSSEC Checker

DNSSEC (Domain Name System Security Extensions) adds cryptographic signatures to DNS records, allowing resolvers to verify that the records have not been tampered with. Without DNSSEC, attackers can forge DNS responses and redirect users to malicious websites through DNS spoofing or cache poisoning attacks. DNSSEC protects against these attacks by creating a chain of trust from the root DNS servers down to your domain. Our DNSSEC checker helps you verify whether a domain has this protection enabled.

Our DNSSEC checker queries DS records (type 43), DNSKEY records (type 48), and RRSIG records (type 46) from Cloudflare's DNS-over-HTTPS (DoH) API. It also checks the AD (Authenticated Data) flag in the DNS response header. DS records show whether DNSSEC is configured at the parent zone level, DNSKEY records show the domain's public keys, and RRSIG records show the digital signatures. If DS records exist and/or the AD flag is set, DNSSEC is enabled for the domain. All queries go directly from your browser - no data is stored on our servers.

DS (Delegation Signer) records are stored in the parent zone (e.g., .com for example.com) and contain a hash of the child zone's DNSKEY. They establish the chain of trust. DNSKEY records contain the public keys used by the domain to sign its DNS records - there are Key Signing Keys (KSK) and Zone Signing Keys (ZSK). RRSIG (Resource Record Signature) records are the actual digital signatures attached to each DNS record set. Together, these three record types form the core of DNSSEC.

The AD (Authenticated Data) flag is a bit in the DNS response header that indicates whether the resolver has successfully validated the DNSSEC signatures for the response. When set to true, it means the resolver verified that the DNS records are authentic and have not been tampered with. If the AD flag is not set and no DS records are found, the domain likely does not have DNSSEC enabled. Our DNSSEC checker displays the AD flag status for every query.

A KSK (Key Signing Key) is a DNSKEY record with flag 257 (the Secure Entry Point flag set). It is used to sign the DNSKEY record set itself - creating a secure entry point that the DS record in the parent zone authenticates. A ZSK (Zone Signing Key) is a DNSKEY record with flag 256. It is used to sign all other records in the zone (A, MX, TXT, etc.). Using separate KSK and ZSK keys allows zone operators to rotate their ZSK more frequently (e.g., monthly) while keeping their KSK stable (e.g., yearly), reducing operational overhead. Our DNSSEC checker labels each DNSKEY record as KSK or ZSK.

Modern DNSSEC best practice recommends using algorithm 13 (ECDSA P-256) or algorithm 15 (Ed25519) for optimal security and performance. Algorithm 8 (RSA/SHA-512) and algorithm 7 (RSA/SHA-256) are also widely supported but have larger key sizes. Older algorithms like 5 (RSA/SHA-1), 3 (DSA/SHA-1), and 1 (RSA/MD5) are considered weak and should not be used. For DS record digests, SHA-256 (digest type 2) is the current standard, while SHA-1 (digest type 1) is being phased out. Our DNSSEC checker displays the algorithm and digest type for each record so you can verify they meet current security standards.

If a domain does not have DNSSEC enabled, its DNS responses are not cryptographically signed. This means an attacker could potentially forge DNS responses for that domain through man-in-the-middle attacks or cache poisoning, redirecting users to malicious servers without detection. While most major domains (Google, Cloudflare, Facebook) have DNSSEC enabled, many smaller domains still do not. Our DNSSEC checker helps you identify unprotected domains so you can assess the risk.

No. All DNS queries are sent directly from your browser to Cloudflare's DNS-over-HTTPS endpoint. We do not store, log, or process your DNS queries on our servers. Cloudflare's privacy policy governs how they handle DoH queries - they commit to not selling query data and deleting logs within 25 hours.

Yes! Our DNSSEC checker is 100% free with no signup, no account, and no usage limits. Check DNSSEC status for any domain as many times as you need - completely free, forever.