DNSSEC record
DNSSEC Checker
Check whether your domain uses DNSSEC, which cryptographically signs your DNS so answers can't be forged - protecting your MX, SPF, DKIM and DMARC records.
Reference
How DNSSEC works
What the record is for, how to read the result, and what to do about each problem.
What is DNSSEC?
DNSSEC adds cryptographic signatures to your DNS. Resolvers can then verify that answers - including your MX, SPF, DKIM and DMARC records - really came from you and weren't tampered with.
How to read the result
Best-effort check: we look for DNSKEY records, which indicate the zone is signed. Full validation up the chain of trust is done by a validating resolver.
How to enable DNSSEC
Turn on DNSSEC at your DNS provider, then publish the resulting DS record at your registrar.
Questions
Frequently asked
What is DNSSEC?
DNSSEC adds cryptographic signatures to your DNS so resolvers can verify answers really came from you and weren't forged. It protects everything in your DNS, including MX, SPF, DKIM and DMARC records.
How do I enable DNSSEC?
Enable DNSSEC at your DNS provider, then add the resulting DS record at your registrar. Many providers do both in one click.
Related checks