⚠ DNS integrity

DNSSEC Checker

Check whether your domain is signed with DNSSEC. DNSSEC adds cryptographic signatures to DNS so resolvers can detect forged answers and cache-poisoning attacks.

check ▸

What DNSSEC does

DNSSEC (DNS Security Extensions) signs your DNS records with keys published as DNSKEY records and builds a chain of trust up to the root zone. A validating resolver rejects any answer whose signature does not check out.

How to read your result

Nattvakt reports a pass when DNSKEY records are present and the answer is authenticated (the resolver's AD flag is set). Keys present but not validated shows as a warning; no keys means DNSSEC is off.

Turning DNSSEC on

Enable signing at your DNS host, then publish the resulting DS record at your registrar to complete the chain of trust.

A DS record without matching keys — or keys without a DS record — breaks resolution, so change them in the right order.

Frequently asked questions

What is DNSSEC?

A set of DNS extensions that sign records cryptographically so resolvers can verify answers were not forged or tampered with in transit.

What is the difference between DNSKEY and DS?

DNSKEY holds the signing keys inside your zone; the DS record at your registrar links your zone to its parent, completing the chain of trust.

Will DNSSEC break my site?

Only if misconfigured — for example a DS record that does not match your keys. Enable signing first, then publish the matching DS record.

// Other free checks
DMARC Checker
Email spoofing protection
SPF Checker
Sender authorization
DKIM Checker
Message signing
SSL Certificate Checker
Certificate & HTTPS
Security Headers Checker
HTTP response headers
DNS Checker
DNS records lookup