Result appears here after you select
{ } How to use
- Enter the domain.
- Select Process.
- Read the summary: it says which of the three parts is missing when DNSSEC is only half set up.
{ } How it works
DNSSEC Checker works on the text you provide. Select Process ▸ and it runs entirely in your browser — nothing is uploaded to a server — then shows the result in the Output panel.
Input
- Domain — paste or type your input in the left panel (use Sample for an example)
Output
TXT text — copy or download it from the Output panel.
{ } Common uses
- Confirm DNSSEC really is on after enabling it at your registrar.
- Diagnose the common half-finished setup, where a domain is signed but the parent has no DS record.
- Check a domain before relying on DANE or TLSA.
{ } Limitations
- This reports what a validating resolver sees. It is not a full chain walk from the root the way DNSViz draws one, so it will tell you that validation failed but not always exactly which key or signature is at fault.
- A resolver that does not validate would answer differently; the check is made against one that does.
{ } FAQ
Is my data uploaded to a server?
No. Everything runs locally in your browser — your files never leave your device.
Can I process more than one file at once?
This tool works on one input at a time.
Is this tool free?
Yes — it’s completely free and needs no sign-up.
My domain publishes a key but the check says DNSSEC is off. Why?
Because a key alone proves nothing. The parent zone has to carry a DS record pointing at that key, which is what links your domain into the chain of trust. Publishing the key and never giving the DS to your registrar is the most common way DNSSEC ends up half-configured — it looks enabled and validates nothing.
Should I turn DNSSEC on?
It stops an attacker forging answers for your domain, which is worth having. The risk is operational rather than theoretical: if the signatures expire or the keys and the DS fall out of step, validating resolvers stop resolving the domain entirely. Turn it on where the registrar or DNS host manages the keys for you.
Is my lookup private?
Your query is sent to a public DNS resolver to answer it. No files are involved and nothing is stored.
Why might results differ from my computer?
Resolvers cache records for the record’s TTL, so a very recent change can take time to appear everywhere. Use the DNS Propagation tool to compare resolvers.