DNS security
DNSSEC checker
See whether a domain's DNS is signed with DNSSEC: whether the parent zone publishes a DS record for it, and whether a public resolver marked the answer as validated. Signed answers let resolvers detect forged DNS responses.
What this checks
- The zone that contains the name you enter: for a subdomain without a zone of its own, the domain above it.
- Whether the parent zone publishes a DS record for that zone, the link your registrar adds when DNSSEC is switched on.
- The DS records found, with their key tag, algorithm and digest type.
- Whether the resolver validated the answer and set the authenticated-data (AD) flag.
What the result means
DNSSEC adds signatures to a zone's records so that a validating resolver can tell a genuine answer from a forged or altered one. Trust runs down from the root: each parent zone vouches for its child with a DS record, a digest of one of the child's keys. Without a DS record at the parent, resolvers treat the zone as unsigned, even if it has keys.
A pass means the parent publishes a DS record for the zone, so DNSSEC is switched on. A finding means no DS record was found, so resolvers cannot validate answers for the zone.
Many domains run without DNSSEC, which is why the finding is a low-severity hardening recommendation rather than an issue. DNSSEC protects against forged answers; it does not encrypt DNS or hide which names are looked up.
How to fix common issues
DNSSEC is not enabled
Enable DNSSEC at your DNS provider, then publish the DS record it gives you at your registrar. Many providers (Cloudflare, Route 53, Azure DNS) can do both in a few clicks.
Cyber Essentials and ISO 27001
Neither Cyber Essentials nor ISO 27001 requires DNSSEC. Where an organisation chooses to use it, the check is technical evidence for broader ISO/IEC 27001:2022 Annex A controls: 8.21 Security of network services, and 8.24 Use of cryptography, since DNSSEC rests on signing keys that someone has to manage.
The organisation still has to decide whether to sign its zones, who holds and rolls the keys or which provider does it for them, and how DNSSEC is handled when the domain moves to another DNS provider or registrar. A DS record shows the setting, not that decision.
Scope and limitations
- It does not fetch DNSKEY records or verify signatures itself. A DS record shows DNSSEC was switched on at the parent, not that every signature behind it is currently valid.
- The validation flag is what one public resolver reported for the answer; it does not test how other resolvers behave.
- It checks the zone, not each name in it, and does not look at zones delegated below it.
Related guides
Questions
- What is a DS record?
- A Delegation Signer record: a digest of one of your zone's DNSSEC keys, usually the key-signing key, published in the parent zone through your registrar. It links the parent's signatures to yours, so resolvers can follow the chain of trust down to your records.
- Can turning on DNSSEC break my domain?
- Yes, if the steps happen out of order. A DS record that does not match the keys your zone is signed with makes validating resolvers reject your answers, and the domain stops resolving for their users. Sign the zone first, then add the DS record. Before moving to another DNS provider, follow its steps for DNSSEC, or remove the DS record and let it expire first.
- Is DNSSEC required for Cyber Essentials or ISO 27001?
- No. Neither names DNSSEC. It is a hardening measure an organisation can choose, and where it does, this check is evidence that it is switched on.
- Does DNSSEC encrypt DNS?
- No. It signs answers so they can be checked, but queries and answers still travel unencrypted. Encrypting DNS traffic is separate, done with DNS over HTTPS or DNS over TLS.
Related security tools
- DNS security checker - Check a domain's address records, nameserver redundancy, CAA, DNSSEC and dangling CNAMEs.
- DNS checker - Look up a domain's A, AAAA, CNAME, MX, TXT, NS, SOA, CAA and DS records through public resolvers.
- CAA checker - See which certificate authorities a domain allows to issue its certificates.
- Website security checker - Check a domain's DNS, email authentication, TLS, security headers and public technology in one pass.

