DNSSEC Checker

Check whether your domain uses DNSSEC, which cryptographically signs your DNS so answers can't be forged - protecting your MX, SPF, DKIM and DMARC records.

Want the full picture - MX, SPF, DKIM, DMARC and more?

Run a full Domain Check

About these results

This tool performs a best-effort DNSSEC check by looking for DNSKEY records; full DNSSEC validation is done by a validating resolver. Results reflect current public DNS and can be affected by caching and propagation (up to 24-48 hours). Guidance is general and not a substitute for your provider's official instructions. We don't store the domains you check.

What is DNSSEC?

DNSSEC adds cryptographic signatures to your DNS. Resolvers can then verify that answers - including your MX, SPF, DKIM and DMARC records - really came from you and weren't tampered with.

How to read the result

Best-effort check: we look for DNSKEY records, which indicate the zone is signed. Full validation up the chain of trust is done by a validating resolver.

How to enable DNSSEC

Turn on DNSSEC at your DNS provider, then publish the resulting DS record at your registrar.

Related checks: Full domain check SPF DKIM DMARC MX lookup MTA-STS TLS-RPT BIMI