DNS Security Checker
A single scan covers the full DNS security surface Nivaronix checks: basic resolution and reverse DNS, SPF and DMARC email authentication, CAA certificate-issuance restrictions, and DNSSEC signing status.
What's included in this scan
- DNS resolution — whether the domain resolves to a valid IP address, and whether reverse DNS (PTR) is configured.
- SPF — missing records, multiple records, hard fail, soft fail, or no usable policy. See the SPF & DMARC checker for detail.
- DMARC — missing records, monitor-only p=none policy, or an invalid policy tag.
- CAA — whether certificate-authority issuance is restricted, or open to any public CA by default.
- DNSSEC — whether the domain is signed, not enabled, or signed but failing to resolve.
Scope of the DNSSEC check
Nivaronix checks whether DNSSEC is enabled — specifically, whether a DS record is published at the parent zone, and whether our resolver's response carried the authenticated-data (AD) flag for that lookup. This is a presence-and-signature-status check, not full chain-of-trust validation from the root down through every intermediate zone. For an independent, full-chain validation view, use a dedicated tool such as dnsviz.net.
About DKIM
DKIM is a separate, complementary email-authentication mechanism that adds a cryptographic signature to outgoing mail. Nivaronix does check DKIM, as part of its DNS checks rather than the SPF/DMARC ones: it queries a short, fixed list of common selectors at <selector>._domainkey.<your-domain> and reports whether a usable DKIM public key is published at one of them. Because DKIM has no directory lookup — the selector name is chosen by whichever platform signs your mail, and there is no way to enumerate it from outside — a "no DKIM record found" result is evidence, not proof: a domain signing with a selector outside that list looks identical to a domain with no DKIM at all. Nivaronix also does not validate DKIM signatures on live mail, so this is a published-key check rather than a full DKIM audit. The DKIM guide lists the exact selectors tried.
Check one thing specifically
Run the full DNS security scan
Free, no signup for a single scan. DNS checks run alongside headers, TLS, and technology detection in one report.
Scan your domain freeDNS records change without warning — a registrar renewal, a provider migration, or a colleague editing the wrong zone. A one-off scan only shows you today's state. Nivaronix's platform monitors SPF, DMARC, CAA, and DNSSEC continuously and alerts you the moment a record drifts.