✓

DNSSEC Checker

Query Cloudflare’s DNS-over-HTTPS resolver for a domain’s DS records and AD flag to report whether the zone is DNSSEC-signed and whether the chain validates.

Queries Cloudflare's DNS-over-HTTPS resolver with the AD bit and checks the DS record set. A domain is DNSSEC-signed when DS records exist; the AD flag confirms the resolver validated the whole chain.

Check DNSSEC for a signed domain

Check a domain known to be DNSSEC-signed and see its DS records plus whether the signed chain validates.

Requires an internet connection. Queries Cloudflare’s resolver with the DNSSEC AD bit set.

FAQ

What is DNSSEC?

It’s a set of extensions that cryptographic-symbolically sign DNS records, so resolvers can verify a response wasn’t tampered with in transit. It protects against DNS spoofing and cache poisoning.

What does the AD flag tell you?

The Authenticated Data (AD) flag means the validating resolver has verified the DNSSEC chain of trust for the answer — a stronger signal than the zone merely having DS records.

DS records vs being signed?

DS (Delegation Signer) records in the parent zone point to the child’s DNSSEC keys, forming the chain of trust. If DS records exist the zone is signed; the AD flag confirms the whole chain validates.

Why might my domain not be signed?

Enabling DNSSEC has to be turned on at both your DNS provider and your registrar (for the DS record). Many hosts don’t enable it by default, so it’s worth enabling to harden your DNS.

Updated 2026-08-10 · Runs in your browser — your data never leaves this page unless the tool explicitly says it makes a network check.