DNS Security Checker
A single scan covers the full DNS security surface Nivaronix checks: basic resolution and reverse DNS, SPF and DMARC email authentication, CAA certificate-issuance restrictions, and DNSSEC signing status.
What's included in this scan
- DNS resolution — whether the domain resolves to a valid IP address, and whether reverse DNS (PTR) is configured.
- SPF — missing records, multiple records, hard fail, soft fail, or no usable policy. See the SPF & DMARC checker for detail.
- DMARC — missing records, monitor-only p=none policy, or an invalid policy tag.
- CAA — whether certificate-authority issuance is restricted, or open to any public CA by default.
- DNSSEC — whether the domain is signed, not enabled, or signed but failing to resolve.
Scope of the DNSSEC check
Nivaronix checks whether DNSSEC is enabled — specifically, whether a DS record is published at the parent zone, and whether our resolver's response carried the authenticated-data (AD) flag for that lookup. This is a presence-and-signature-status check, not full chain-of-trust validation from the root down through every intermediate zone. For an independent, full-chain validation view, use a dedicated tool such as dnsviz.net.
About DKIM
DKIM is a separate, complementary email-authentication mechanism that adds a cryptographic signature to outgoing mail. Nivaronix currently does not perform DKIM verification — this scan checks SPF and DMARC only. If you need DKIM validated, use your mail provider's DKIM test tool or a dedicated mail-auth checker.
Check one thing specifically
Run the full DNS security scan
Free, no signup for a single scan. DNS checks run alongside headers, TLS, and technology detection in one report.
Scan your domain free