DNSSEC Checker
Check whether your domain uses DNSSEC, which cryptographically signs your DNS so answers can't be forged - protecting your MX, SPF, DKIM and DMARC records.
Want the full picture - MX, SPF, DKIM, DMARC and more?
Run a full Domain CheckAbout these results
This tool performs a best-effort DNSSEC check by looking for DNSKEY records; full DNSSEC validation is done by a validating resolver. Results reflect current public DNS and can be affected by caching and propagation (up to 24-48 hours). Guidance is general and not a substitute for your provider's official instructions. We don't store the domains you check.What is DNSSEC?
DNSSEC adds cryptographic signatures to your DNS. Resolvers can then verify that answers - including your MX, SPF, DKIM and DMARC records - really came from you and weren't tampered with.
How to read the result
Best-effort check: we look for DNSKEY records, which indicate the zone is signed. Full validation up the chain of trust is done by a validating resolver.
How to enable DNSSEC
Turn on DNSSEC at your DNS provider, then publish the resulting DS record at your registrar.