DNSSEC Checker
Enter a domain and Nivaronix looks up its DS record at the parent zone to report whether DNSSEC is enabled, not enabled, or — the case that matters most — signed but currently failing to resolve.
What this checker reports
- DNSSEC enabled — a DS record is published at the parent zone, so responses for the domain are signed.
- DNSSEC not enabled — no DS record is published, so answers are unsigned and a validating resolver cannot detect tampering.
- Signed but unresolved — a DS record exists but the domain failed to resolve during the scan, which is the signature of a stale or mismatched DS record breaking resolution for everyone behind a validating resolver.
- Status could not be verified— the DS lookup itself timed out or failed; this is reported as inconclusive, never as "not enabled."
What this check does not do
Nivaronix checks whether DNSSEC is enabled — specifically, whether a DS record is published at the parent zone, and whether our resolver's response carried the authenticated-data (AD) flag for that lookup. This is a presence-and-signature-status check, not full chain-of-trust validation from the root down through every intermediate zone. For an independent, full-chain validation view, use a dedicated tool such as dnsviz.net.
Learn more
Check your domain's DNSSEC status
Free, no signup for a single scan. DNSSEC is part of every full Nivaronix scan alongside SPF, DMARC, CAA, headers, and TLS.
Scan your domain free