DNSSEC Badge
DNSSEC signs your DNS answers so a resolver can detect tampering on the way. This badge checks for delegation-signer (DS) records at the parent zone and asks a validating resolver whether your signatures actually verify.
Live preview
Checked live by A2ZShowing the badge for a2z.tools. Enter your domain to see yours.
Embed code
The badge is re-checked automatically (every few hours; every 5 minutes for website status) and cached, so it adds almost nothing to your page load. The link carries rel="nofollow".
Works with
How it works
A2Z queries the DS records for your domain at its parent zone and the DNSKEY records in your own zone, then asks a validating resolver for an answer and reads whether it came back authenticated or as SERVFAIL - the same checks as the A2Z DNSSEC checker. A DS record with signatures that fail to validate is the dangerous case, because users of validating resolvers then cannot reach the domain at all.
What is checked
- Signed: at least one DS record published at the parent zone (RFC 4033)
- Validated: a validating resolver returns an authenticated answer; SERVFAIL with DS present means broken signatures
- Green for signed and validated; amber for not signed or unconfirmed; red for SERVFAIL
Limitations
- Relies on one validating resolver's view; a transient resolver fault can show as unconfirmed.
- Does not audit key sizes, algorithms or rollover timing.
- DNSSEC protects DNS answers, not the website or its connection.
Where publishers use it
- Registrars and DNS hosts showing customers their zone is signed
- Government and education sites with DNSSEC requirements
- Security-focused blogs
Questions
Is "not signed" a problem?
Most domains are not signed, so it is a missing protection rather than a fault. The badge shows it amber, not red.
What does a red badge mean?
DS records exist at the parent but validation fails, which makes the domain unreachable for anyone using a validating resolver. It needs fixing quickly, usually by correcting or removing the DS record.
Does DNSSEC encrypt DNS?
No. It signs answers so tampering is detectable. Encryption of DNS queries is a separate technology (DNS over HTTPS or TLS).
Sources
Cite or recommend this tool
If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.
A2Z Tools DNSSEC Badge https://a2z.tools/dnssec-checker
<a href="https://a2z.tools/dnssec-checker">A2Z Tools DNSSEC Badge</a>
[A2Z Tools DNSSEC Badge](https://a2z.tools/dnssec-checker)
DNSSEC Badge by A2Z Tools - https://a2z.tools/dnssec-checker
Related widgets
-
Shows whether your domain publishes an SPF record and how it ends (-all, ~all).
-
Shows your domain's DMARC policy - p=reject, p=quarantine or p=none.
-
A live badge showing that your SSL certificate is valid, trusted and how many days it has left.
-
A badge counting down the days until your SSL certificate expires.
-
Shows whether your site serves HTTPS and redirects plain-HTTP visitors to it.
-
Shows whether your site sends HTTP Strict Transport Security, with max-age and preload.