DNSSEC Checker
Check whether a domain publishes DNSSEC records and whether the signature chain validates.
Need to monitor this across every client domain you manage? ActiScan does bulk scanning, scoring, and white-labeled reporting for MSPs.
How to Use the DNSSEC Checker
Enter a domain
No http:// prefix – just the domain itself (e.g. company.com).
Click Check
ActiScan looks up the domain's DNSKEY record live, over DNS.
Read the result
A pass/warn/info status plus a plain-English explanation of what it means.
What Your Result Means
DNSSEC validatedPassA DNSKEY record exists and the resolver's response carried the AD (Authenticated Data) flag – the resolver's own attestation that it verified the full signature chain for this query.
DNSKEY present, not validatedWarnA DNSKEY record exists, but the resolver couldn't validate the signature chain. Usually a broken or missing DS record at the registrar, or an expired signature – check both.
DNSSEC not configuredInfoNo DNSKEY record found – this domain isn't using DNSSEC. Not required, but signing your zone prevents DNS spoofing and cache-poisoning attacks for anyone who wants the extra assurance.
What Is DNSSEC?
DNSSEC (Domain Name System Security Extensions) adds cryptographic signatures to DNS records so a resolver can verify that the answer it received actually came from the zone's legitimate owner and wasn't tampered with in transit – the kind of DNS spoofing and cache-poisoning attack DNSSEC exists to prevent.
A signed zone publishes DNSKEY records (its public keys) and RRSIG records (signatures over its data), plus a DS record at the parent zone that anchors the chain of trust all the way up to the root.
How this checker works, honestly: it asks a DNS resolver for the domain's DNSKEY record and reads two things – whether a DNSKEY exists at all, and whether the resolver's response carries the AD ("Authenticated Data") flag. That flag is the resolver's own attestation that it independently validated the full RRSIG/DS signature chain for this query. We're relying on the resolver's already-completed validation work rather than re-implementing RRSIG/DS signature-chain verification ourselves – the same trust boundary your own recursive resolver relies on for every DNSSEC-aware lookup you make. It's an accurate signal, but it does mean this tool can't tell you which specific part of a broken chain failed – just that it didn't validate.
DNSSEC Record Types Explained
| Record | What it does | Where it lives |
|---|---|---|
| DNSKEY | The zone's public key(s), published in the zone itself. What this checker looks up. | Published at the domain |
| DS | A hash of the child zone's DNSKEY. Anchors the chain of trust from parent to child. | Published at the registry/parent zone |
| RRSIG | A cryptographic signature over a set of records, proving they haven't been altered. | Published alongside the records it signs |
| NSEC / NSEC3 | Lets a resolver authentically prove a name doesn't exist, instead of just trusting an unsigned "not found." | Published at the domain |
How to Check DNSSEC Manually
If you'd rather look it up yourself instead of using the checker above:
Check for a DNSKEY record
dig DNSKEY yourdomain.com +short
Check the AD (validated) flag
dig @1.1.1.1 yourdomain.com +dnssec
Look for ad in the flags line of the response header.
Next Steps After Your Check
Want to check other DNS records?
Look up A, MX, TXT, NS, and more for any domain – or reverse-lookup an IP.
DNS Record Checker →Want to see who manages this domain?
A WHOIS/RDAP lookup shows the registrar, nameservers, and whether the registry has a signed delegation on file.
WHOIS Lookup →Want ongoing monitoring?
ActiScan scans on a schedule and alerts you when something changes – across every domain you manage.
Start free →Frequently Asked Questions
Is this DNSSEC checker free?
Yes – check any domain for free, no signup required.
Do I need DNSSEC?
It's not required, but it closes a real gap: without it, a resolver has no way to verify that the DNS answers it receives haven't been tampered with or spoofed. Most registrars and DNS hosts can enable it in a few clicks.
Why does my domain show "DNSKEY present, not validated"?
The domain published a DNSKEY, but the DS record at the registry either doesn't match it, is missing, or a signature has expired. Check the DS record at your registrar first – that's the most common cause.
Does DNSSEC stop phishing or spoofed "From" addresses?
No – that's a different layer. DNSSEC protects DNS lookups themselves from tampering; SPF, DKIM, and DMARC are what authenticate who's allowed to send mail as your domain.
How do I enable DNSSEC on my domain?
Turn it on with your DNS host (they'll sign the zone and generate a DS record), then add that DS record at your domain registrar to complete the chain of trust.