Skip to content

DNS security

DNSSEC checker

See whether a domain's DNS is signed with DNSSEC: whether the parent zone publishes a DS record for it, and whether a public resolver marked the answer as validated. Signed answers let resolvers detect forged DNS responses.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

DNSSEC adds signatures to a zone's records so that a validating resolver can tell a genuine answer from a forged or altered one. Trust runs down from the root: each parent zone vouches for its child with a DS record, a digest of one of the child's keys. Without a DS record at the parent, resolvers treat the zone as unsigned, even if it has keys.

A pass means the parent publishes a DS record for the zone, so DNSSEC is switched on. A finding means no DS record was found, so resolvers cannot validate answers for the zone.

Many domains run without DNSSEC, which is why the finding is a low-severity hardening recommendation rather than an issue. DNSSEC protects against forged answers; it does not encrypt DNS or hide which names are looked up.

How to fix common issues

DNSSEC is not enabled

Enable DNSSEC at your DNS provider, then publish the DS record it gives you at your registrar. Many providers (Cloudflare, Route 53, Azure DNS) can do both in a few clicks.

More in the DNSSEC check reference

Cyber Essentials and ISO 27001

Neither Cyber Essentials nor ISO 27001 requires DNSSEC. Where an organisation chooses to use it, the check is technical evidence for broader ISO/IEC 27001:2022 Annex A controls: 8.21 Security of network services, and 8.24 Use of cryptography, since DNSSEC rests on signing keys that someone has to manage.

The organisation still has to decide whether to sign its zones, who holds and rolls the keys or which provider does it for them, and how DNSSEC is handled when the domain moves to another DNS provider or registrar. A DS record shows the setting, not that decision.

Scope and limitations

Related guides

Questions

What is a DS record?
A Delegation Signer record: a digest of one of your zone's DNSSEC keys, usually the key-signing key, published in the parent zone through your registrar. It links the parent's signatures to yours, so resolvers can follow the chain of trust down to your records.
Can turning on DNSSEC break my domain?
Yes, if the steps happen out of order. A DS record that does not match the keys your zone is signed with makes validating resolvers reject your answers, and the domain stops resolving for their users. Sign the zone first, then add the DS record. Before moving to another DNS provider, follow its steps for DNSSEC, or remove the DS record and let it expire first.
Is DNSSEC required for Cyber Essentials or ISO 27001?
No. Neither names DNSSEC. It is a hardening measure an organisation can choose, and where it does, this check is evidence that it is switched on.
Does DNSSEC encrypt DNS?
No. It signs answers so they can be checked, but queries and answers still travel unencrypted. Encrypting DNS traffic is separate, done with DNS over HTTPS or DNS over TLS.

Related security tools