DNSSEC Trust Chain Analyzer & Validator
Audit a domain's Domain Name System Security Extensions (DNSSEC) configuration. Verify DS records at the parent TLD, DNSKEY records, RRSIG cryptographic signatures, and parent-child chain of trust.
What Is DNSSEC & How Does the Chain of Trust Work?
DNSSEC (DNS Security Extensions) (RFC 4033 / RFC 4034 / RFC 4035) adds cryptographic signatures to DNS records to protect resolvers against DNS spoofing, cache poisoning, and man-in-the-middle attacks.
Key Cryptographic Record Types
- DS (Delegation Signer): A hash digest of the child zone's KSK published in the parent zone (e.g. at the TLD registrar) to establish top-down authentication.
- DNSKEY: Contains public keys used to verify signatures: the Key Signing Key (KSK) and Zone Signing Key (ZSK).
- RRSIG (Resource Record Signature): The digital signature covering a specific DNS record set (RRset).
- NSEC / NSEC3: Provides authenticated denial of existence for non-existent subdomains.