Emergency server help: get in touch

DNSSEC Checker

Check whether a domain is signed with DNSSEC: DS records at the registry, DNSKEY records in the zone, matching key tags, algorithms and live validation through Cloudflare and Google.

Status
Live
Last updated
October 3, 2026

DNSSEC signs DNS answers so resolvers can detect forged responses. It only works when the DS record at your registrar matches a key published in your zone. This tool reads both, matches them by key tag and asks two validating resolvers whether the domain validates.

Reading the results

A DS record with no matching DNSKEY is the classic broken setup: it happens when a domain moves to a new DNS provider but the old DS stays at the registrar. Validating resolvers such as 1.1.1.1 and 8.8.8.8 then answer SERVFAIL, so the whole domain disappears for a large share of internet users even though your name servers look fine.

Algorithm 13 (ECDSA P-256 SHA-256) is the current recommendation because of its small signatures; algorithm 8 (RSASHA256) is still widely used. Algorithms 5 and 7 (SHA-1) are deprecated and should be rolled over.

Changing DNS provider safely

Remove the DS record at the registrar first and wait at least the DS TTL (often 1–2 days). Move the name servers, enable signing at the new provider, then add the new DS record it gives you. Cloudflare, cPanel with PowerDNS and DirectAdmin all show the DS values to copy.

DNSSEC checker at a glance

DNSSEC Checker summary card: DNSSEC signs DNS answers so resolvers can detect forged responses.
In short: DNSSEC signs DNS answers so resolvers can detect forged responses.
DNSSEC Checker sections: Reading the results and Changing DNS provider safely
Covers: Reading the results and Changing DNS provider safely.
DNSSEC Checker questions answered: Does DNSSEC slow down my site? Why do some resolvers still answer for a broken domain?
Answers: Does DNSSEC slow down my site? Why do some resolvers still answer for a broken domain?

Official documentation: AlmaLinux wiki, Linux man pages.

Related guides: CSF on AlmaLinux 10: nftables compatibility, ipset limits and workarounds · Copy Fail, Dirty Frag and Fragnesia: mitigating the 2026 Linux privilege-escalation trio without a reboot · Installing Sentinel Firewall as a drop-in CSF replacement on Ubuntu 24.04 and Debian 13.

Frequently asked questions

Does DNSSEC slow down my site?

No noticeable difference for visitors. Answers are slightly larger, which is why ECDSA keys are preferred.

Why do some resolvers still answer for a broken domain?

Only validating resolvers reject bad signatures. Many ISP resolvers do not validate, which is why a broken DNSSEC setup can look fine from one network and fail from another.

What is the AD flag?

Authenticated Data: a validating resolver sets it when the answer’s signatures verified all the way from the root.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.