DNSSEC Explained: How to Check If a Domain Is Signed

The Problem DNSSEC Solves

Classic DNS has no way to prove that an answer is genuine. An attacker who can inject or alter DNS responses can send users to a fake server. Cache poisoning attacks, such as the widely publicized Kaminsky attack in 2008, showed how practical this can be.

DNSSEC (DNS Security Extensions) adds digital signatures to DNS records. A validating resolver can check those signatures and refuse answers that have been tampered with. You can check any domain with our DNSSEC Checker.

What DNSSEC Does and Does Not Do

  • It does protect the integrity and authenticity of DNS answers.
  • It does not encrypt DNS queries. For privacy, protocols such as DNS over HTTPS (DoH) and DNS over TLS (DoT) are used.
  • It does not protect the connection to the website itself. HTTPS still does that.

The Records Involved

  • DNSKEY: the public keys of a zone, published in the zone itself.
  • RRSIG: the signatures attached to each set of records.
  • DS (Delegation Signer): a fingerprint of the zone’s key, published in the parent zone (for example.com, in the .com zone).
  • NSEC / NSEC3: signed proof that a name does not exist, so attackers cannot forge “does not exist” answers.

The Chain of Trust

Validation starts at the DNS root, whose key is built into validating resolvers. The root signs the DS record of .com, the .com zone signs the DS record of example.com, and example.com signs its own records. If every link checks out, the answer is marked as authentic. If any link is broken, a validating resolver returns SERVFAIL and the domain stops resolving for users of that resolver.

How to Check If a Domain Is Signed

A domain is properly signed when:

  1. The parent zone has a DS record for it.
  2. The domain publishes DNSKEY records that match the DS record.
  3. Its records carry valid, unexpired RRSIG signatures.

Our DNSSEC Checker looks at these records. A domain with DNSKEY records but no DS record at the parent is signed but not anchored, so resolvers treat it as unsigned.

Common Causes of DNSSEC Outages

  • Changing DNS provider without updating the DS record. The new provider signs with new keys, but the old DS record still sits at the registry. Validating resolvers then reject every answer. Always remove or replace the DS record as part of the move.
  • Expired signatures: signatures have validity periods. If automatic re-signing stops, the zone eventually fails.
  • Key rollover mistakes: replacing keys in the wrong order breaks the chain.

Because major public resolvers validate DNSSEC, these mistakes can make a domain unreachable for a large share of users at once.

Should You Enable DNSSEC?

If your DNS provider and registrar support DNSSEC with automatic signing and simple DS management, enabling it is usually straightforward and improves security. The main risk is operational: remember that the DS record exists whenever you change DNS providers or registrars.

Related Tools