DNSSEC Record Analyzer

Inspect only DS, DNSKEY and RRSIG records and their cryptographic fields.

Resolved Target:

-

TypeHost / NameTarget / ValueTTL
No records loaded.

How to use this tool

Displays and parses only DS, DNSKEY and RRSIG records at the entered owner. Includes key tags, algorithms, digest data, flags, covered record types and signature timing when supplied. Use the status checker for chain validation.

Enter the target, complete any relevant options and choose Check. Review the requested records, query outcomes and diagnostic findings. Copy Report saves the visible report.

Reading the results

No matching records and an unavailable query are different outcomes. TTLs are displayed in seconds; zero is a valid TTL. A completed request does not mean a domain passed its health checks. Only the submitted DNS owner and explicitly listed checks are inspected.

Frequently Asked Questions

Does this analyzer parse DS, DNSKEY, or RRSIG fields?

No. The visible output uses a generic DNS table and has no fields for algorithms, key tags, digests, signatures, or inception dates.

Why do I only see ordinary DNS records?

The server performs a general DNS request, and the browser fallback is limited to A, AAAA, MX, TXT, NS, and SOA queries.

Can the table verify a DS digest against a DNSKEY?

No. The implementation contains no digest calculation or parent-to-child key comparison.

Does an empty table mean DNSSEC is disabled?

No. It means this resolver path supplied no displayable records for the name. It is not a DNSSEC status result.

Can this output reveal an expired RRSIG?

No. Signature expiry and inception values are not retrieved into dedicated fields or evaluated by the page.

What can I confirm with this page?

You can confirm the submitted domain and examine the ordinary DNS rows returned for it. Use a DNSSEC-aware validator for cryptographic findings.