DNSSEC Trust Chain Analyzer & Validator | iN2 Tools

Audit a domain's DNSSEC setup, including DS and DNSKEY records, signature validation, and parent-child trust confirmation.

DNSSEC Trust Chain Analyzer & Validator

Audit a domain's Domain Name System Security Extensions (DNSSEC) configuration. Verify DS records at the parent TLD, DNSKEY records, RRSIG cryptographic signatures, and parent-child chain of trust.

What Is DNSSEC & How Does the Chain of Trust Work?

DNSSEC (DNS Security Extensions) (RFC 4033 / RFC 4034 / RFC 4035) adds cryptographic signatures to DNS records to protect resolvers against DNS spoofing, cache poisoning, and man-in-the-middle attacks.

Key Cryptographic Record Types

  • DS (Delegation Signer): A hash digest of the child zone's KSK published in the parent zone (e.g. at the TLD registrar) to establish top-down authentication.
  • DNSKEY: Contains public keys used to verify signatures: the Key Signing Key (KSK) and Zone Signing Key (ZSK).
  • RRSIG (Resource Record Signature): The digital signature covering a specific DNS record set (RRset).
  • NSEC / NSEC3: Provides authenticated denial of existence for non-existent subdomains.

Related DNS & Security Tools