DNSSEC Validator
DNS Security Diagnostic
DNSSEC Validator
Check for DS delegation, DNSKEY records and whether a validating DNS-over-HTTPS resolver authenticated the DNSKEY response.
DNSSEC is a chain, not a “record present” checkbox
A zone can publish DNSKEY records and still fail validation if the parent delegation does not contain the matching DS information or signatures are broken. Conversely, a domain with no DS delegation is simply unsigned rather than necessarily misconfigured.
This check asks a validating resolver for both sides of that evidence and exposes the resolver's Authenticated Data result. I would use it for fast diagnosis and deployment checks, then reach for a full delegation/signature debugger when a signed zone fails validation.
