Skip to content

DNSSEC Checker

Enter a domain and Nivaronix looks up its DS record at the parent zone to report whether DNSSEC is enabled, not enabled, or — the case that matters most — signed but currently failing to resolve.

What this checker reports

  • DNSSEC enabled — a DS record is published at the parent zone, so responses for the domain are signed.
  • DNSSEC not enabled — no DS record is published, so answers are unsigned and a validating resolver cannot detect tampering.
  • Signed but unresolved — a DS record exists but the domain failed to resolve during the scan, which is the signature of a stale or mismatched DS record breaking resolution for everyone behind a validating resolver.
  • Status could not be verified— the DS lookup itself timed out or failed; this is reported as inconclusive, never as "not enabled."

What this check does not do

Nivaronix checks whether DNSSEC is enabled — specifically, whether a DS record is published at the parent zone, and whether our resolver's response carried the authenticated-data (AD) flag for that lookup. This is a presence-and-signature-status check, not full chain-of-trust validation from the root down through every intermediate zone. For an independent, full-chain validation view, use a dedicated tool such as dnsviz.net.

Learn more

Check your domain's DNSSEC status

Free, no signup for a single scan. DNSSEC is part of every full Nivaronix scan alongside SPF, DMARC, CAA, headers, and TLS.

Scan your domain free

See everything Nivaronix's website security scanner checks