Skip to main content

Look at the DNS response for verification flags; unsigned does not mean verification failed.

Only public DNS records are supported, please do not fill in internal or sensitive domain names.

No query has been made, filling in or loading examples will not initiate a request.

Instructions for use

  1. Enter the domain name, query A response and view the AD verification flag.
  2. This tool requests DNSSEC information and keeps resolver verification turned on without re-verifying signatures in the browser.
  3. View records, TTL, status and query time, which can be copied or cleared; modifying the input will cancel the old query.

Input and output examples

Example input
example.com,A
Example output
AD=true: The parser marks this response as verified

The above is a demonstration only, not real-time results. Public DNS records change, and an empty response has different meanings than a failed query.

FAQ

No. May not be signed, etc.; SERVFAIL may have other reasons as well. AD=true can be used for authenticated NXDOMAIN, which does not mean that the name must exist.

Calculation basis and reference materials

This tool requests DNSSEC information and keeps resolver verification turned on without re-verifying signatures in the browser.

Content check: · About this site and content description

Related tools