DNSSEC Badge

DNSSEC signs your DNS answers so a resolver can detect tampering on the way. This badge checks for delegation-signer (DS) records at the parent zone and asks a validating resolver whether your signatures actually verify.

Website & Security SVG badge Checked by A2Z server Free · no ads

Customize your badge

The badge is checked for this domain. Enter the site you will show it on.
Style
Colours
Size

Live preview

Checked live by A2Z
DNSSEC Badge for a2z.tools

Showing the badge for a2z.tools. Enter your domain to see yours.

Embed code

The badge is re-checked automatically (every few hours; every 5 minutes for website status) and cached, so it adds almost nothing to your page load. The link carries rel="nofollow".

Works with

How it works

A2Z queries the DS records for your domain at its parent zone and the DNSKEY records in your own zone, then asks a validating resolver for an answer and reads whether it came back authenticated or as SERVFAIL - the same checks as the A2Z DNSSEC checker. A DS record with signatures that fail to validate is the dangerous case, because users of validating resolvers then cannot reach the domain at all.

What is checked

  • Signed: at least one DS record published at the parent zone (RFC 4033)
  • Validated: a validating resolver returns an authenticated answer; SERVFAIL with DS present means broken signatures
  • Green for signed and validated; amber for not signed or unconfirmed; red for SERVFAIL

Limitations

  • Relies on one validating resolver's view; a transient resolver fault can show as unconfirmed.
  • Does not audit key sizes, algorithms or rollover timing.
  • DNSSEC protects DNS answers, not the website or its connection.

Where publishers use it

  • Registrars and DNS hosts showing customers their zone is signed
  • Government and education sites with DNSSEC requirements
  • Security-focused blogs

Questions

Is "not signed" a problem?

Most domains are not signed, so it is a missing protection rather than a fault. The badge shows it amber, not red.

What does a red badge mean?

DS records exist at the parent but validation fails, which makes the domain unreachable for anyone using a validating resolver. It needs fixing quickly, usually by correcting or removing the DS record.

Does DNSSEC encrypt DNS?

No. It signs answers so tampering is detectable. Encryption of DNS queries is a separate technology (DNS over HTTPS or TLS).

Sources

  1. RFC 4033 - DNS Security Introduction and Requirements (DNSSEC) - IETF

Cite or recommend this tool

If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.

A2Z Tools DNSSEC Badge
https://a2z.tools/dnssec-checker

Preview