Skip to content

DNS configuration

What is DNSSEC?

Whether the parent zone publishes a DS record for the domain, which is what makes its DNS answers signed and checkable by resolvers.

Part of the External Security Check. Free during the preview.

What it checks

Whether the parent zone publishes a DS record for the domain, which is what makes its DNS answers signed and checkable by resolvers.

A pass means: The domain is signed with DNSSEC.

Possible findings

DNSSEC is not enabled

Severity: LowConfidence: High confidenceKind: Recommended hardening

What we found

No DS record was found for the domain at its parent zone, so DNS answers for it are not signed.

Why it matters

DNSSEC lets resolvers detect forged DNS answers. Without it, an attacker able to tamper with DNS traffic could redirect visitors or mail. Many domains run safely without it, so this is a hardening recommendation.

How to fix it

Enable DNSSEC at your DNS provider, then publish the DS record it gives you at your registrar. Many providers (Cloudflare, Route 53, Azure DNS) can do both in a few clicks.

References