Skip to content

DNS security

DNS security checker

Check the parts of a domain's DNS that affect its security: whether its names resolve, how many nameservers serve the zone, which certificate authorities it allows, whether it is signed with DNSSEC, and whether any CNAME points at a name that no longer exists.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

DNS decides where your website, mail and other services are found, so a mistake in it reaches everything under the domain. This check reads the public answers anyone can see and judges five settings that are often wrong or left at their defaults.

A pass means the setting was found as expected. Most findings here are hardening recommendations: a missing CAA record or an unsigned zone is common and not a fault on its own, and the finding explains what adding it would change.

A dangling CNAME is different. It usually means a hosted service was removed but its DNS record was left behind, and it is raised to High when the target is on a platform where someone else may be able to claim the name. Deal with it first.

How to fix common issues

CNAME points at a name that does not exist

Remove the CNAME record if the service is no longer used, or recreate the resource it points at. Review DNS whenever a hosted service is retired.

More in the Dangling DNS records check reference

Only one nameserver

Delegate the domain to at least two nameservers, ideally on separate networks. Most managed DNS providers supply two or more by default.

More in the Nameserver redundancy check reference

No CAA records

Add a CAA record naming the certificate authorities you use, for example example.com. CAA 0 issue "letsencrypt.org". Check which authorities issue your current certificates first, so renewals keep working.

More in the CAA records check reference

DNSSEC is not enabled

Enable DNSSEC at your DNS provider, then publish the DS record it gives you at your registrar. Many providers (Cloudflare, Route 53, Azure DNS) can do both in a few clicks.

More in the DNSSEC check reference

Domain has no address records

No action is needed if the domain is not meant to serve a website. Otherwise add A and/or AAAA records at your DNS provider.

More in the Address records check reference

Cyber Essentials and ISO 27001

Neither Cyber Essentials nor ISO 27001 names CAA, DNSSEC or dangling records, and Cyber Essentials does not cover DNS records directly. For ISO/IEC 27001:2022, these results are technical evidence for broader Annex A controls: 8.9 Configuration management, 8.21 Security of network services, and 5.9 Inventory of information and other associated assets, which a record left pointing at a retired service shows has fallen behind.

The organisation still has to establish who owns the domain and its DNS, how changes to records are approved, and how records are reviewed and removed when a service is retired. The check shows the records as they are today, not the process behind them.

Scope and limitations

Related guides

Questions

How many nameservers should a domain have?
At least two. RFC 1034 expects every zone to be served by more than one nameserver, and most managed DNS providers give you two or more. Ideally they sit on separate networks; this check counts the names and does not test that.
Do I need DNSSEC and CAA records?
Neither is required, and many domains run without them, which is why their findings are low-severity hardening recommendations. CAA limits which certificate authorities may issue certificates for the domain; DNSSEC lets resolvers detect forged DNS answers.
Does this check change anything or contact my servers?
No. It makes ordinary DNS lookups through public resolvers and changes nothing. It does not connect to your web or mail servers.

Related security tools