DNSSEC (Domain Name System Security Extensions) protects DNS from spoofing. Verification = confirm the domain publishes DNSKEY and a DS record in the TLD, and the signature chain is valid. Tools: online DNS checkers, dig +dnssec, delv, Verisign DNSSEC Analyzer.
Below: step-by-step, working examples, common pitfalls, FAQ.
dig +dnssec +short example.com DNSKEY for keys; dig +dnssec example.com DS for DS recordsdig +dnssec +trace example.com — trace from rootdelv @8.8.8.8 example.com — "fully validated" = OK| Scenario | Config / Record |
|---|---|
| Properly signed domain | dig +dnssec example.com → answer contains RRSIG + "ad" flag (Authenticated Data) |
| Unsigned domain | dig +dnssec → NO RRSIG in answer. DS record missing from TLD |
| Broken DNSSEC | delv reports "no valid signature" or "DNSKEY could not be retrieved" |
| Via 1.1.1.1 (validating) | dig @1.1.1.1 example.com → SERVFAIL = signature invalid |
dig +dnssec shows records but does not validate — use delv or +traceDNS (Domain Name System) translates domain names into IP addresses. DNS records are instructions that define where to route traffic, email, and how to verify domainownership.
Query all record types — A, AAAA, MX, NS, TXT, CNAME, SOA — in a single request.
Direct queries to authoritative servers. Results in milliseconds, no caching.
SPF, DKIM, and DMARC analysis to evaluate email protection against spoofing and phishing.
Save check results. Compare DNS records before and after registrar changes.
DNS check after deploy
SPF/DKIM/DMARC audit
DNS config audit
DNS zone control
v=spf1 TXT record.DNS check history, API keys and DNS change monitoring.
Sign up freeAuthenticated Data — the resolver's flag. If set, the resolver validated the signature and it is correct.
Yes. HTTPS protects transit, DNSSEC protects name resolution. Without DNSSEC an attacker can forge the IP → you land on their HTTPS site with their cert → no protection.
Not every resolver validates. Unbound, BIND, PowerDNS — yes. dnsmasq (home routers) — often no. Test via 1.1.1.1.
Only 4.1% of .ru domains. See the <a href="/en/s/research-dnssec-adoption-runet-2026">Enterno research</a>.