DNSSEC signs DNS answers so resolvers can detect forged responses. It only works when the DS record at your registrar matches a key published in your zone. This tool reads both, matches them by key tag and asks two validating resolvers whether the domain validates.
Table of Contents
Reading the results
A DS record with no matching DNSKEY is the classic broken setup: it happens when a domain moves to a new DNS provider but the old DS stays at the registrar. Validating resolvers such as 1.1.1.1 and 8.8.8.8 then answer SERVFAIL, so the whole domain disappears for a large share of internet users even though your name servers look fine.
Algorithm 13 (ECDSA P-256 SHA-256) is the current recommendation because of its small signatures; algorithm 8 (RSASHA256) is still widely used. Algorithms 5 and 7 (SHA-1) are deprecated and should be rolled over.
Changing DNS provider safely
Remove the DS record at the registrar first and wait at least the DS TTL (often 1–2 days). Move the name servers, enable signing at the new provider, then add the new DS record it gives you. Cloudflare, cPanel with PowerDNS and DirectAdmin all show the DS values to copy.
DNSSEC checker at a glance



Official documentation: AlmaLinux wiki, Linux man pages.
Related guides: CSF on AlmaLinux 10: nftables compatibility, ipset limits and workarounds · Copy Fail, Dirty Frag and Fragnesia: mitigating the 2026 Linux privilege-escalation trio without a reboot · Installing Sentinel Firewall as a drop-in CSF replacement on Ubuntu 24.04 and Debian 13.
Frequently asked questions
Does DNSSEC slow down my site?
No noticeable difference for visitors. Answers are slightly larger, which is why ECDSA keys are preferred.
Why do some resolvers still answer for a broken domain?
Only validating resolvers reject bad signatures. Many ISP resolvers do not validate, which is why a broken DNSSEC setup can look fine from one network and fail from another.
What is the AD flag?
Authenticated Data: a validating resolver sets it when the answer’s signatures verified all the way from the root.