DNS & EMAIL

DNSSEC Validation

Use a validating DNS-over-HTTPS resolver to see whether a domain response is authenticated, unsigned or broken.

39DExternal testRuns from the toolbox server

RUN TEST

DNSSEC Validation

Public targets only

HOW IT WORKS

About the DNSSEC Validation

DNSSEC adds signatures to DNS data and links zones through DS records. A validating resolver sets the authenticated-data indicator when the chain validates. A bad signature or incorrect DS record can make a signed domain unreachable to validating users.

How to use this result

  1. Run the test from this server.Use a public hostname, address, prefix or ASN in the format requested above.
  2. Compare with another observation point.Run a local command or use a second provider to identify location-specific behaviour.
  3. Correlate related evidence.Use the related tools below to compare DNS, routes, ports, TLS and application responses.
  4. Keep the time and context.Routing, DNS caches and reputation data change, so record when the result was collected.

Common interpretation issues

  • Publishing a DS record before the child zone is correctly signed can cause a validation failure.
  • Expired signatures can break an otherwise correct zone.
  • Unsigned domains can still resolve; they simply lack DNSSEC authentication.

NEED HELP INTERPRETING THE RESULT?

39D supports business networks, cyber security and managed IT.

For ongoing support or a larger infrastructure project, speak to the 39D team.

Visit 39D

Frequently asked questions

Does DNSSEC encrypt DNS?

No. It authenticates DNS data; encrypted transport is provided separately by DoH or DoT.

What is the most dangerous migration mistake?

Leaving an old DS record at the parent after changing or disabling signing.