DNSSEC Checker

Check DNSSEC records for a domain

Look for the DNSSEC records that make a signed delegation work: DS at the parent, DNSKEY at the zone apex, and RRSIG signatures over signed record sets.

Run DNSSEC Check
Enter a domain to query DS, DNSKEY, and RRSIG records.

Use the zone apex for the clearest DS and DNSKEY result. Examples: , , ,

Frequently asked questions

What does a DNSSEC checker verify?

DNS Buddy checks whether a domain publishes DNSSEC chain evidence in DNS: DS records at the parent zone, DNSKEY records in the child zone, and optionally RRSIG signatures. It shows what is visible to resolvers, not full cryptographic validation end-to-end.

What is the difference between DS and DNSKEY records?

DS (Delegation Signer) records live in the parent zone and point to keys in the child zone. DNSKEY records contain the actual public keys used to verify signatures within the zone.

Why might RRSIG records be missing in a lookup?

Some resolvers refuse direct RRSIG queries or only return signatures as part of DNSSEC-validated responses. DNS Buddy reports what each public resolver returns so you can see published evidence.

Read the DNSSEC record guide or look up individual record types via DS, DNSKEY, and RRSIG lookups.