DNSSEC
Learn how DNSSEC uses DS, DNSKEY, and RRSIG records to authenticate DNS answers, what each record means, and how to check whether a domain publishes DNSSEC evidence.
TL;DR DNSSEC adds cryptographic signatures to DNS so resolvers can verify that DNS answers were not changed in transit. A working DNSSEC chain usually has a DS record at the parent zone, DNSKEY records at the signed zone, and RRSIG records that sign DNS record sets.
Use the DNSSEC Checker for a combined DS, DNSKEY, and RRSIG check. For individual records, you can also query:
dig example.com DS
dig example.com DNSKEY +dnssec
dig example.com RRSIG +dnssec