Check DNSSEC

Enter a domain. The DNSSEC checker verifies whether a DS record exists in the parent zone, whether a validating resolver confirms the signature chain (AD flag) and whether the domain is bogus, meaning signed but not validatable.

What is DNSSEC?

DNSSEC (DNS Security Extensions) cryptographically signs DNS answers. Every zone owns a key pair used to sign its records (RRSIG). The public key (DNSKEY) is anchored in the parent zone through a DS record, which in turn is signed by the parent, all the way up to the root zone. A validating resolver follows this chain and detects forged or tampered answers.

DNSSEC therefore protects against cache poisoning and DNS spoofing, attacks that silently redirect users to a foreign IP without the browser noticing. It is also a prerequisite for DANE, which lets mail servers publish their certificates via DNS.

The three states

The checker distinguishes three outcomes:

  • Not signed: no DS record in the parent zone. The domain is reachable but unprotected. For most domains this is the normal state, not an error.
  • Validated: DS record present and a validating resolver confirms the chain (AD flag set). Everything is correct.
  • Bogus: DS record present but validation fails. Validating resolvers answer SERVFAIL. This is the critical case.

Why bogus is the most dangerous DNS error

If the DS record in the parent zone does not match the DNSKEY in the zone, or the signatures have expired, every validating resolver rejects the answer. Google Public DNS, Cloudflare, Quad9 and the resolvers of most ISPs validate. For their users the domain simply ceases to exist: no website, no mail, no subdomains.

The insidious part: the office computer often uses a resolver without validation, and there everything works. The problem only surfaces when clients call. Typical triggers are a hosting migration where the DS record stays at the registry while the new zone has no matching keys, or an expired key after an unfinished rotation.

What a DS record looks like

The DS record lives in the parent zone (for example.com that is the .com registry) and contains key tag, algorithm, digest type and the hash of the DNSKEY. A typical record with ECDSA P-256 (algorithm 13) and SHA-256 (digest type 2):

example.com. IN DS 2371 13 2 1F987CC6583E92DF0890718C42A5A1E64E4F3F1A9A5A3C4B7B8C2D3E4F5A6B7C

Enabling DNSSEC and changing providers safely

Signing is almost always handled by the DNS host; you only need to place the DS record with your registrar. When changing DNS hosts the order matters: first remove the DS record at the registry, wait for the parent zone TTL to expire, then move the zone, and only then add the new DS record. If you leave the DS record in place and move the zone, the domain is bogus for hours or days.

  • Before every DNS migration, check whether the domain is signed.
  • Remove the DS record, wait for the TTL (often 24 hours at the registry), then migrate.
  • After the migration add the new DS record and validate it with this checker.
  • Prefer algorithm 13 (ECDSA P-256) over 8 (RSA): smaller answers, same security.

Monitor DNSSEC continuously

A domain never goes bogus on purpose. It happens during migrations, key rotations or when a host changes its signing setup. DomainWarn checks the DNSSEC chain of all client domains regularly, reports a broken state immediately as a critical incident and also notices when DNSSEC was switched off unnoticed.

Frequently asked questions

Do I need DNSSEC at all?
For a normal company website DNSSEC is optional; the domain works without it. It makes sense for domains using DANE for mail and wherever DNS manipulation is a realistic risk. What matters most is that a signed domain never becomes bogus.
Why does my domain work for me but not for clients?
That is the classic picture of a bogus domain: your resolver does not validate, theirs does. Check the DS record at the registry and the DNSKEY records in the zone. After a recent migration, removing and re-adding the DS record usually fixes it.
How long until a DS record takes effect?
The registry usually publishes it within minutes to a few hours. Resolver caches keep old answers until the TTL expires, so it can take up to a day until all users see the new state.

Add the DNSSEC at IONOS, STRATO, Hetzner, Cloudflare and others

The path to the DNS editor differs by host. For the common providers this shows where you create the DNSSEC and what to watch out for.

DNSSEC at IONOS

  1. Sign in to the IONOS account and open "Domains & SSL".
  2. Click the gear icon next to the domain and choose "DNS".
  3. Choose "Add record", pick the type (TXT, MX, CNAME) and host name, paste the value, save.
  4. Changes usually apply within minutes; the default TTL is one hour.

Use "@" as the host name for the apex domain; IONOS shows it as the domain name.

DNSSEC at STRATO

  1. In the STRATO customer login open "Domains" and then "Domain administration".
  2. Choose "manage" next to the domain and switch to the "DNS settings" tab.
  3. STRATO separates by type: "TXT and CNAME records" for SPF, DKIM, DMARC and verifications, "MX records" for mail delivery.
  4. Enter the value and save; propagation can take up to an hour.

For subdomain records such as _dmarc or selector._domainkey put the prefix into the "Subdomain" field, not into the value.

DNSSEC at Hetzner

  1. Open the Hetzner DNS Console (dns.hetzner.com) and select the zone of the domain.
  2. Choose "Add record", enter type, name and value, lower the TTL if needed.
  3. Save; the Hetzner name servers serve the record immediately.

DNSSEC at ALL-INKL

  1. Sign in to KAS (the customer administration system) and open "Domain".
  2. Click "edit" next to the domain and then "DNS settings".
  3. "Create new DNS record", enter name (empty for the apex), type and value, save.
  4. ALL-INKL applies changes within minutes.

DNSSEC at Cloudflare

  1. In the Cloudflare dashboard open the domain and choose "DNS" → "Records".
  2. Choose "Add record" and enter type, name and content.
  3. For MX, TXT and mail-related CNAME records keep the proxy status on "DNS only"; the orange cloud belongs to web records only.
  4. Save; Cloudflare propagates instantly.

DNSSEC at netcup

  1. In the netcup Customer Control Panel (CCP) open "Domains" and select the domain.
  2. Switch to the "DNS" tab and choose "Add new record".
  3. Enter host (@ for the apex), type and destination, then "Save DNS records".

DNSSEC at united-domains

  1. In the united-domains portfolio click the domain and open "DNS settings".
  2. Under "Custom DNS records" choose the type, enter subdomain and value.
  3. Save; propagation takes a few minutes.

DNSSEC at checkdomain

  1. In the checkdomain customer area open "Domains" and select the domain.
  2. Open "DNS settings" and create a new record with type, name and value.
  3. Save.

DNSSEC at domainfactory

  1. In the domainfactory customer menu open "Domains" and select the domain.
  2. Open "Name server settings" and create a new record.
  3. Enter type, host name and value, save.

DNSSEC at Alfahosting

  1. In the Alfahosting customer center open the domain and choose "DNS management".
  2. Create a new record with type, name and value, save.

DNSSEC at webgo

  1. In the webgo customer portal open "Domains" and choose "DNS management" next to the domain.
  2. Create a record with type, name and value, save.

DNSSEC at 1blu

  1. In the 1blu customer service area open "Domains" and choose "DNS settings" next to the domain.
  2. Create a record with type, name and value, save.

DNSSEC at Host Europe

  1. In KIS (the customer information system) open "Domain services" and then "Domain administration".
  2. Choose "Name server / DNS" next to the domain and create the record with type, name and value.
  3. Save.

DNSSEC at Mittwald

  1. In mStudio open the project and select the domain under "Domains".
  2. Open "DNS", edit or create the record, save.

DNSSEC at GoDaddy

  1. At GoDaddy open "My Products" and choose "DNS" next to the domain.
  2. Choose "Add", enter type, name and value, save.

DNSSEC at Hostinger

  1. In hPanel open "Domains" and choose "DNS / Nameservers" next to the domain.
  2. In the DNS zone editor create the record with type, name and value.

DNSSEC at Amazon Route 53

  1. In the AWS console open Route 53, "Hosted zones" and select the zone.
  2. Choose "Create record", enter name, type and value, set the TTL, "Create records".

DNSSEC at Google Cloud DNS

  1. In the Google Cloud console open "Cloud DNS" and select the zone.
  2. "Add record set", enter name, type and value, create.

DNSSEC at Azure DNS

  1. In the Azure portal open "DNS zones" and select the zone.
  2. Add a "Record set", enter name, type and value, OK.

DNSSEC at OVHcloud

  1. In the OVHcloud control panel open "Web Cloud" → "Domain names" and the domain.
  2. Tab "DNS zone", "Add an entry", choose the type, enter subdomain and value, confirm.

DNSSEC at DigitalOcean

  1. In the DigitalOcean dashboard open "Networking" → "Domains" and select the domain.
  2. Choose the type, enter host name and value, "Create Record".

DNSSEC at Squarespace

  1. At Squarespace open "Domains", select the domain and open "DNS settings".
  2. Under "Custom records" create the record with type, host and data.

DNSSEC at Wix

  1. In the Wix account open "Domains" and choose "Manage DNS records" next to the domain.
  2. Under the matching type choose "Add record", enter host name and value, save.

DNSSEC at Shopify

  1. In the Shopify admin open "Settings" → "Domains" and select the domain.
  2. Open "DNS settings", "Add custom record", enter type, name and value, confirm.

DNSSEC at INWX

  1. At INWX open "Nameserver" and select the domain.
  2. "Add record", enter type, name and value, save.

DNSSEC at dogado

  1. In the dogado customer area open the domain and choose "DNS".
  2. Create the record with type, name and value, save.

DNSSEC at Variomedia

  1. In the Variomedia customer menu open the domain and choose "DNS settings".
  2. Create the record with type, name and value, save.

DNSSEC at Namecheap

  1. At Namecheap open "Domain List", "Manage" and the "Advanced DNS" tab.
  2. "Add New Record", enter type, host and value, save.

DNSSEC at Gandi

  1. At Gandi open the domain and choose "DNS records".
  2. "Add a record", enter type, name and value, create.

DNSSEC at Vercel

  1. In the Vercel dashboard open "Domains" and select the domain.
  2. Under "DNS Records" enter type, name and value, "Add".

Guides for this tool

More tools

Free tool

SPF Checker

Free SPF record check and lookup: syntax, includes, the 10 DNS lookup limit and the closing qualifier. Shows whether your domain blocks forged senders.

Open tool →
Free tool

DMARC Checker

Free DMARC record check and lookup: policy (none, quarantine, reject), pct, reporting addresses and syntax errors. With recommendations for moving to p=reject.

Open tool →
Free tool

DNS Checker

Free DNS lookup straight from the authoritative name server: A, AAAA, CNAME, MX, TXT, NS and CAA records at a glance. No sign-up, every record explained.

Open tool →
Free tool

MX Checker

Free MX lookup: which mail servers receive for a domain, do they resolve, is the priority right? Detects missing and unreachable mail servers.

Open tool →
Free tool

SSL Checker

Free SSL certificate check: expiry date, issuer, chain, host name, alternative names and TLS version. Detects expired, self-signed and mismatched certificates.

Open tool →
Free tool

HTTP Header Checker

Free HTTP header check: HSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy with recommendations.

Open tool →
Free tool

Redirect Checker

Free 301 redirect check: every hop with status code and response time, from http to https, from www to non-www. Detects redirect chains, loops and 302s.

Open tool →
Free tool

DKIM Checker

Free DKIM record check and lookup: selector, key type, key length, syntax and revoked keys. Leave the selector empty to try common selectors automatically.

Open tool →
Free tool

MTA-STS Checker

Free MTA-STS check: DNS record, policy file, mode, max_age and whether your MX servers are covered. Shows whether inbound mail enforces TLS.

Open tool →
Free tool

TLS-RPT Checker

Free TLS-RPT record check: syntax, reporting addresses (rua) and common errors such as a missing record. Shows whether you get reports on TLS failures.

Open tool →
Free tool

BIMI Checker

Free BIMI record check: syntax, logo URL, SVG Tiny PS, VMC certificate and the DMARC prerequisite. Shows why your logo does not appear in Gmail.

Open tool →
Free tool

Blacklist Check

Free IP blacklist and domain blacklist check: mail server IPs, website IP and domain against Spamhaus, Spamcop, Barracuda, PSBL and SURBL. With delisting links.

Open tool →
Free tool

Domain Checker

Free domain check: expiry date, registrar, EPP status, transfer lock and name servers straight from the registry via RDAP. Warns about expiry and holds.

Open tool →