DNSSEC Lookup Tool

Check DNSSEC records instantly across global resolvers to validate your cryptographic signatures and Chain of Trust.

How to troubleshoot DNSSEC and SERVFAIL errors

If your website suddenly drops off the internet for users on major ISPs (like Google DNS or Cloudflare), but works fine for others, you likely have a broken DNSSEC configuration. Enter your domain name above to query its DNSSEC status. This tool helps you verify if your cryptographic signatures match the parent zone.

Interpreting your DNSSEC results

  • The Dreaded SERVFAIL: If a validating resolver (like 8.8.8.8) detects that your DNSSEC signatures are invalid or expired, it will completely block access to your domain and return a SERVFAIL status to protect users from potential hijacking.
  • Domain Transfers: The #1 cause of DNSSEC outages is transferring a domain to a new host without removing the old DS (Delegation Signer) record at your registrar first. The parent zone will still expect the old host's cryptographic keys, causing a mismatch.
  • Missing DS Records: If the lookup shows DNSKEYs but no DS record at the parent TLD, your zone is signed, but the "Chain of Trust" is incomplete. DNSSEC is effectively inactive until you upload the DS record to your registrar.

DNSSEC lookup for DS and DNSKEY records

DNSSEC adds cryptographic validation to DNS, protecting against tampering and spoofing. The DNSKEY record holds the public keys for the zone, while DS records in the parent zone create the chain of trust. A DNSSEC lookup helps you confirm that both DNSKEY and DS records are published and consistent across resolvers.

Common DNSSEC issues include mismatched DS and DNSKEY values, expired signatures, or missing DS records at the registrar. These problems often show as validation failures or bogus responses. Use this lookup to review DNSSEC data and compare what different resolvers return during rollovers.

If you need related checks, try SSL/PKI DNS check lookup and SOA record DNS lookup.

DNSKEY is published in the zone itself. DS is published in the parent zone and links to the DNSKEY, creating the chain of trust.

It means DNSSEC is not fully enabled at the parent. You must publish DS records at the registrar or parent zone for validation to work.

Bogus indicates validation failed. It can be caused by mismatched keys, expired signatures, or missing DS records.

Key rotation policies vary, but regular rollovers are best practice. Always follow your provider guidance and ensure DS updates are synchronized.

DNSSEC itself does not break the site, but misconfiguration can cause validating resolvers to reject responses, making the domain appear unreachable for some users.

Yes. TLSA relies on DNSSEC validation to be trustworthy.