DNSSEC Validator
Inspect DNSSEC deployment, resolver validation, DS/DNSKEY/RRSIG records, and the delegation chain for a domain.
Chain of Trust
DNSSEC Records
Resolver Evidence
How to read the result
The validating resolver returned authenticated data and the DNSSEC records required for validation were found.
The domain resolves but no validated DNSSEC chain is established. This is not the same as a DNSSEC failure.
A validating resolver could not validate the response, commonly because of a DS/DNSKEY/signature mismatch, expiry, or broken delegation.
The tool did not receive enough evidence to make a reliable classification. Check resolver/network availability and retry.
DNSSEC troubleshooting flow
Important: This tool is a diagnostic assistant, not an authoritative certification service. Public resolvers can cache data, and resolver behavior can differ. For production incidents, compare results with authoritative servers and a second validating resolver.
Your feedback matters