The DNSSEC Checker is a specialized diagnostic utility that tests whether a domain is protected with Domain Name System Security Extensions and displays its DS records. It queries authoritative name servers to validate cryptographic signatures and ensure your domain resolution path is secure against tampering.
What is it
DNSSEC stands for Domain Name System Security Extensions. It is a suite of specifications created by the Internet Engineering Task Force (IETF) to add a layer of cryptographic security to the traditional Domain Name System. When you query a standard DNS record, your resolver trusts the response it receives, which leaves the communication vulnerable to cache poisoning and man-in-the-middle attacks where malicious actors can forge IP addresses and redirect your traffic.
This tool inspects the chain of trust from the root servers down to your authoritative name servers. It checks for the presence of DNSKEY, RRSIG, and DS (Delegation Signer) records. By validating these public key signatures, the tool confirms whether resolvers can cryptographically verify that the DNS data they received actually came from you and was not altered in transit.
Why it matters
Implementing DNSSEC is critical for maintaining the integrity and authenticity of your organization's online presence. Without it, attackers can spoof DNS responses and route your users to fraudulent websites that mimic your login pages, steal credentials, or intercept emails. For businesses handling sensitive transactions or managing high-value domains, DNSSEC provides an essential layer of defense that stops cache poisoning at the protocol level.
Furthermore, modern validating resolvers actively check for DNSSEC signatures. If your domain has broken DNSSEC configuration—often referred to as a "bogus" state—validating resolvers will refuse to resolve your domain entirely, rendering your website and services completely inaccessible to large portions of the internet. Regularly checking your configuration prevents unexpected outages caused by expired keys or mismatched records.
How to use this tool
- Navigate to the XiaTools DNSSEC Checker page.
- Locate the search input box on the screen.
- Enter your fully qualified domain name, such as
example.com, without the http:// protocol prefix. - Click the Check button to initiate the diagnostic query.
- Review the resulting cryptographic chain of trust and recorded parameters displayed on your screen.
How to read the results
When you run a check for example.com, the tool returns several key data points that describe the cryptographic health of your zone. Understanding these values helps you determine if your domain is fully secure or if configuration errors exist.
- DNSSEC Status: Shows whether DNSSEC is enabled and valid. A status of
SECUREmeans the chain of trust is intact. A status ofINSECUREmeans DNSSEC is not deployed. A status ofBOGUSindicates a broken cryptographic configuration that will cause resolution failures. - DS Record (Delegation Signer): Displays the fingerprint of the Key Signing Key (KSK) that your domain registrar holds in the parent zone (like .com). For example, you might see
12345 8 2 AABBCCDD11223344.... This contains the Key Tag (12345), Algorithm (8 for RSA/SHA-256), and Digest Type (2 for SHA-256), along with the cryptographic hash. - DNSKEY Records: Lists the public keys published by your name servers. You will typically see a Zone Signing Key (ZSK) and a Key Signing Key (KSK).
- Key Tag: A numeric identifier used to efficiently distinguish among multiple DNSKEY records in the same zone, such as
40123. - Algorithm: The cryptographic algorithm used to generate the keys and signatures, such as
13(ECDSA P-256 with SHA-256) or8(RSA/SHA-256).
Common problems and how to fix them
Bogus Chain of Trust
A bogus status occurs when the public keys published in your authoritative zone do not match the DS records registered at your domain registrar. This usually happens after a key rollover where the registrar was not updated with the new DS record. To fix this, generate your current DS records from your DNS provider and update them in your domain registrar's control panel.
Missing Parent-Child Synchronization
If you change your DNS hosting provider and enable DNSSEC on the new provider without updating the DS records at your registrar, validation fails. Ensure the DS record at your registrar matches the KSK currently published by your active name server:
example.com. 3600 IN DS 40123 13 2 9F86D081884C7D659A2FEAA0C55AD015A3BF4F1B2B0B822CD15D6C15B0F00A08
Expired Signatures
DNSSEC signatures (RRSIG records) have a validity period and must be actively renewed by your DNS provider. If your provider's signing daemon fails, signatures expire, leading to resolution failures. Switch to a reliable DNS provider that automates NSEC3/NSEC rolling and signature generation.
Best practices
- Perform routine checks using this tool after every DNS provider migration or key rollover event.
- Use modern cryptographic algorithms such as ECDSA (Algorithm 13 or 14) instead of older RSA variants for better performance and smaller packet sizes.
- Set up automated monitoring and alerts for your domain's DNSSEC status to catch expired keys or invalid signatures before they cause downtime.
- Coordinate key rollovers carefully by maintaining overlapping valid periods for old and new keys to prevent transient resolution errors.