XiaTools
DNS tool

DNSSEC Checker

Test whether a domain is protected with DNSSEC and view its DS records.

The DNSSEC Checker is a specialized diagnostic utility that tests whether a domain is protected with Domain Name System Security Extensions and displays its DS records. It queries authoritative name servers to validate cryptographic signatures and ensure your domain resolution path is secure against tampering.

What is it

DNSSEC stands for Domain Name System Security Extensions. It is a suite of specifications created by the Internet Engineering Task Force (IETF) to add a layer of cryptographic security to the traditional Domain Name System. When you query a standard DNS record, your resolver trusts the response it receives, which leaves the communication vulnerable to cache poisoning and man-in-the-middle attacks where malicious actors can forge IP addresses and redirect your traffic.

This tool inspects the chain of trust from the root servers down to your authoritative name servers. It checks for the presence of DNSKEY, RRSIG, and DS (Delegation Signer) records. By validating these public key signatures, the tool confirms whether resolvers can cryptographically verify that the DNS data they received actually came from you and was not altered in transit.

Why it matters

Implementing DNSSEC is critical for maintaining the integrity and authenticity of your organization's online presence. Without it, attackers can spoof DNS responses and route your users to fraudulent websites that mimic your login pages, steal credentials, or intercept emails. For businesses handling sensitive transactions or managing high-value domains, DNSSEC provides an essential layer of defense that stops cache poisoning at the protocol level.

Furthermore, modern validating resolvers actively check for DNSSEC signatures. If your domain has broken DNSSEC configuration—often referred to as a "bogus" state—validating resolvers will refuse to resolve your domain entirely, rendering your website and services completely inaccessible to large portions of the internet. Regularly checking your configuration prevents unexpected outages caused by expired keys or mismatched records.

How to use this tool

  1. Navigate to the XiaTools DNSSEC Checker page.
  2. Locate the search input box on the screen.
  3. Enter your fully qualified domain name, such as example.com, without the http:// protocol prefix.
  4. Click the Check button to initiate the diagnostic query.
  5. Review the resulting cryptographic chain of trust and recorded parameters displayed on your screen.

How to read the results

When you run a check for example.com, the tool returns several key data points that describe the cryptographic health of your zone. Understanding these values helps you determine if your domain is fully secure or if configuration errors exist.

Common problems and how to fix them

Bogus Chain of Trust

A bogus status occurs when the public keys published in your authoritative zone do not match the DS records registered at your domain registrar. This usually happens after a key rollover where the registrar was not updated with the new DS record. To fix this, generate your current DS records from your DNS provider and update them in your domain registrar's control panel.

Missing Parent-Child Synchronization

If you change your DNS hosting provider and enable DNSSEC on the new provider without updating the DS records at your registrar, validation fails. Ensure the DS record at your registrar matches the KSK currently published by your active name server:

example.com. 3600 IN DS 40123 13 2 9F86D081884C7D659A2FEAA0C55AD015A3BF4F1B2B0B822CD15D6C15B0F00A08

Expired Signatures

DNSSEC signatures (RRSIG records) have a validity period and must be actively renewed by your DNS provider. If your provider's signing daemon fails, signatures expire, leading to resolution failures. Switch to a reliable DNS provider that automates NSEC3/NSEC rolling and signature generation.

Best practices

Frequently asked questions

What is DNSSEC and why do I need it?

DNSSEC adds cryptographic signatures to DNS records, protecting your domain against cache poisoning and man-in-the-middle attacks. It ensures that users who look up your domain actually reach your legitimate servers and not a malicious imposter.

What does a 'Bogus' DNSSEC status mean?

A bogus status means that DNSSEC is enabled, but there is a mismatch in the cryptographic chain of trust—usually because the DS record at your registrar does not match the DNSKEY published by your name server. Resolvers will treat bogus domains as unreachable.

How often should I check my domain's DNSSEC configuration?

You should run a check whenever you change your DNS hosting provider, update your name servers, or perform a key rollover. Routine monthly checks are also recommended to ensure signatures have not expired.

What is a DS record and where is it stored?

A Delegation Signer (DS) record is a fingerprint of your zone's Key Signing Key. It must be published in the parent zone, which means you store it at your domain registrar so the global root and top-level domain can verify your zone.

Does this tool check all of my name servers?

Yes, the tool queries your authoritative name servers to inspect the active DNSKEY and RRSIG records, while also validating the parent zone's DS record to ensure end-to-end cryptographic integrity.

Will enabling DNSSEC slow down my website?

Enabling DNSSEC slightly increases the size of DNS responses because of the added cryptographic signatures. However, this has a negligible impact on load times and vastly improves the security posture of your infrastructure.

DNSSEC Checker guides

Related tools