Skip to content

DNS Security Checker

A single scan covers the full DNS security surface Nivaronix checks: basic resolution and reverse DNS, SPF and DMARC email authentication, CAA certificate-issuance restrictions, and DNSSEC signing status.

What's included in this scan

  • DNS resolution — whether the domain resolves to a valid IP address, and whether reverse DNS (PTR) is configured.
  • SPF — missing records, multiple records, hard fail, soft fail, or no usable policy. See the SPF & DMARC checker for detail.
  • DMARC — missing records, monitor-only p=none policy, or an invalid policy tag.
  • CAA — whether certificate-authority issuance is restricted, or open to any public CA by default.
  • DNSSEC — whether the domain is signed, not enabled, or signed but failing to resolve.

Scope of the DNSSEC check

Nivaronix checks whether DNSSEC is enabled — specifically, whether a DS record is published at the parent zone, and whether our resolver's response carried the authenticated-data (AD) flag for that lookup. This is a presence-and-signature-status check, not full chain-of-trust validation from the root down through every intermediate zone. For an independent, full-chain validation view, use a dedicated tool such as dnsviz.net.

About DKIM

DKIM is a separate, complementary email-authentication mechanism that adds a cryptographic signature to outgoing mail. Nivaronix currently does not perform DKIM verification — this scan checks SPF and DMARC only. If you need DKIM validated, use your mail provider's DKIM test tool or a dedicated mail-auth checker.

Check one thing specifically

Run the full DNS security scan

Free, no signup for a single scan. DNS checks run alongside headers, TLS, and technology detection in one report.

Scan your domain free

See everything Nivaronix's website security scanner checks