ActiScan

DNSSEC Checker

Check whether a domain publishes DNSSEC records and whether the signature chain validates.

Need to monitor this across every client domain you manage? ActiScan does bulk scanning, scoring, and white-labeled reporting for MSPs.

How to Use the DNSSEC Checker

1

Enter a domain

No http:// prefix – just the domain itself (e.g. company.com).

2

Click Check

ActiScan looks up the domain's DNSKEY record live, over DNS.

3

Read the result

A pass/warn/info status plus a plain-English explanation of what it means.

What Your Result Means

DNSSEC validatedPass

A DNSKEY record exists and the resolver's response carried the AD (Authenticated Data) flag – the resolver's own attestation that it verified the full signature chain for this query.

DNSKEY present, not validatedWarn

A DNSKEY record exists, but the resolver couldn't validate the signature chain. Usually a broken or missing DS record at the registrar, or an expired signature – check both.

DNSSEC not configuredInfo

No DNSKEY record found – this domain isn't using DNSSEC. Not required, but signing your zone prevents DNS spoofing and cache-poisoning attacks for anyone who wants the extra assurance.

What Is DNSSEC?

DNSSEC (Domain Name System Security Extensions) adds cryptographic signatures to DNS records so a resolver can verify that the answer it received actually came from the zone's legitimate owner and wasn't tampered with in transit – the kind of DNS spoofing and cache-poisoning attack DNSSEC exists to prevent.

A signed zone publishes DNSKEY records (its public keys) and RRSIG records (signatures over its data), plus a DS record at the parent zone that anchors the chain of trust all the way up to the root.

How this checker works, honestly: it asks a DNS resolver for the domain's DNSKEY record and reads two things – whether a DNSKEY exists at all, and whether the resolver's response carries the AD ("Authenticated Data") flag. That flag is the resolver's own attestation that it independently validated the full RRSIG/DS signature chain for this query. We're relying on the resolver's already-completed validation work rather than re-implementing RRSIG/DS signature-chain verification ourselves – the same trust boundary your own recursive resolver relies on for every DNSSEC-aware lookup you make. It's an accurate signal, but it does mean this tool can't tell you which specific part of a broken chain failed – just that it didn't validate.

DNSSEC Record Types Explained

RecordWhat it doesWhere it lives
DNSKEYThe zone's public key(s), published in the zone itself. What this checker looks up.Published at the domain
DSA hash of the child zone's DNSKEY. Anchors the chain of trust from parent to child.Published at the registry/parent zone
RRSIGA cryptographic signature over a set of records, proving they haven't been altered.Published alongside the records it signs
NSEC / NSEC3Lets a resolver authentically prove a name doesn't exist, instead of just trusting an unsigned "not found."Published at the domain

How to Check DNSSEC Manually

If you'd rather look it up yourself instead of using the checker above:

Check for a DNSKEY record

dig DNSKEY yourdomain.com +short

Check the AD (validated) flag

dig @1.1.1.1 yourdomain.com +dnssec

Look for ad in the flags line of the response header.

Next Steps After Your Check

Want to check other DNS records?

Look up A, MX, TXT, NS, and more for any domain – or reverse-lookup an IP.

DNS Record Checker →

Want to see who manages this domain?

A WHOIS/RDAP lookup shows the registrar, nameservers, and whether the registry has a signed delegation on file.

WHOIS Lookup →

Want ongoing monitoring?

ActiScan scans on a schedule and alerts you when something changes – across every domain you manage.

Start free →

Frequently Asked Questions

Is this DNSSEC checker free?

Yes – check any domain for free, no signup required.

Do I need DNSSEC?

It's not required, but it closes a real gap: without it, a resolver has no way to verify that the DNS answers it receives haven't been tampered with or spoofed. Most registrars and DNS hosts can enable it in a few clicks.

Why does my domain show "DNSKEY present, not validated"?

The domain published a DNSKEY, but the DS record at the registry either doesn't match it, is missing, or a signature has expired. Check the DS record at your registrar first – that's the most common cause.

Does DNSSEC stop phishing or spoofed "From" addresses?

No – that's a different layer. DNSSEC protects DNS lookups themselves from tampering; SPF, DKIM, and DMARC are what authenticate who's allowed to send mail as your domain.

How do I enable DNSSEC on my domain?

Turn it on with your DNS host (they'll sign the zone and generate a DS record), then add that DS record at your domain registrar to complete the chain of trust.

Use the free DNSSEC checker as often as you need

Start free trial