What it checks
Whether the parent zone publishes a DS record for the domain, which is what makes its DNS answers signed and checkable by resolvers.
A pass means: The domain is signed with DNSSEC.
Possible findings
DNSSEC is not enabled
Severity: LowConfidence: High confidenceKind: Recommended hardening
What we found
No DS record was found for the domain at its parent zone, so DNS answers for it are not signed.
Why it matters
DNSSEC lets resolvers detect forged DNS answers. Without it, an attacker able to tamper with DNS traffic could redirect visitors or mail. Many domains run safely without it, so this is a hardening recommendation.
How to fix it
Enable DNSSEC at your DNS provider, then publish the DS record it gives you at your registrar. Many providers (Cloudflare, Route 53, Azure DNS) can do both in a few clicks.

