DNS security
DNS security checker
Check the parts of a domain's DNS that affect its security: whether its names resolve, how many nameservers serve the zone, which certificate authorities it allows, whether it is signed with DNSSEC, and whether any CNAME points at a name that no longer exists.
What this checks
- Address records: the A and AAAA records for the domain and its
www.name, or for a subdomain, that name only. A domain with none is reported for information, since it may be used only for email. - Nameserver redundancy: the NS records at the zone apex, which pass with two or more distinct nameservers.
- CAA: the records at the domain, then at each parent up to the zone apex, where a certificate authority looks for them (RFC 8659).
- DNSSEC: whether the parent zone publishes a DS record for the zone, and whether the resolver validated the answer.
- Dangling CNAMEs: for each name checked, whether its CNAME chain ends in a name that does not exist.
What the result means
DNS decides where your website, mail and other services are found, so a mistake in it reaches everything under the domain. This check reads the public answers anyone can see and judges five settings that are often wrong or left at their defaults.
A pass means the setting was found as expected. Most findings here are hardening recommendations: a missing CAA record or an unsigned zone is common and not a fault on its own, and the finding explains what adding it would change.
A dangling CNAME is different. It usually means a hosted service was removed but its DNS record was left behind, and it is raised to High when the target is on a platform where someone else may be able to claim the name. Deal with it first.
How to fix common issues
CNAME points at a name that does not exist
Remove the CNAME record if the service is no longer used, or recreate the resource it points at. Review DNS whenever a hosted service is retired.
Only one nameserver
Delegate the domain to at least two nameservers, ideally on separate networks. Most managed DNS providers supply two or more by default.
No CAA records
Add a CAA record naming the certificate authorities you use, for example example.com. CAA 0 issue "letsencrypt.org". Check which authorities issue your current certificates first, so renewals keep working.
DNSSEC is not enabled
Enable DNSSEC at your DNS provider, then publish the DS record it gives you at your registrar. Many providers (Cloudflare, Route 53, Azure DNS) can do both in a few clicks.
Domain has no address records
No action is needed if the domain is not meant to serve a website. Otherwise add A and/or AAAA records at your DNS provider.
Cyber Essentials and ISO 27001
Neither Cyber Essentials nor ISO 27001 names CAA, DNSSEC or dangling records, and Cyber Essentials does not cover DNS records directly. For ISO/IEC 27001:2022, these results are technical evidence for broader Annex A controls: 8.9 Configuration management, 8.21 Security of network services, and 5.9 Inventory of information and other associated assets, which a record left pointing at a retired service shows has fallen behind.
The organisation still has to establish who owns the domain and its DNS, how changes to records are approved, and how records are reviewed and removed when a service is retired. The check shows the records as they are today, not the process behind them.
Scope and limitations
- It reads public DNS through public resolvers and does not query your nameservers directly, so it sees what those resolvers return, not the configuration at your DNS provider.
- It checks the domain and its
www.name, or the one subdomain you enter. Other subdomains are not discovered or checked; the subdomain finder lists names from certificate logs. - The nameserver check counts distinct nameserver names. It does not test whether they are on separate networks.
- The DNSSEC check looks for a DS record and the resolver's validation flag. It does not fetch keys or verify the chain of signatures itself.
Related guides
Questions
- How many nameservers should a domain have?
- At least two. RFC 1034 expects every zone to be served by more than one nameserver, and most managed DNS providers give you two or more. Ideally they sit on separate networks; this check counts the names and does not test that.
- Do I need DNSSEC and CAA records?
- Neither is required, and many domains run without them, which is why their findings are low-severity hardening recommendations. CAA limits which certificate authorities may issue certificates for the domain; DNSSEC lets resolvers detect forged DNS answers.
- Does this check change anything or contact my servers?
- No. It makes ordinary DNS lookups through public resolvers and changes nothing. It does not connect to your web or mail servers.
Related security tools
- DNS checker - Look up a domain's A, AAAA, CNAME, MX, TXT, NS, SOA, CAA and DS records through public resolvers.
- Subdomain finder - Find a domain's subdomains in public certificate transparency logs.
- Email security checker - Check MX, SPF, DMARC and DKIM together, and the protection of a domain that sends no mail.
- Website security checker - Check a domain's DNS, email authentication, TLS, security headers and public technology in one pass.

