IPTOOL TR My IP

DNS

DNSKEY and DNSSEC key lookup

DNSSEC: DNSKEY (KSK/ZSK), algorithm, parent DS. Paste a URL.

Daily queries 0 / 40

40 queries left

Sign up → 200/day · Pro → 5000/day Sign up / see Pro

Domain
TLD
Resolver

https://example.com or www.example.com can be pasted; www is dropped. Resolver chips: Google, Cloudflare, Quad9. This is not a full RRSIG walk.

Queries leave from this Linux server, not your ISP DNS. Free. Cached answers can differ for a short time.

DNSKEY, KSK, ZSK and DS

DNSSEC signs the zone. DNSKEY flag 257 is KSK, 256 is ZSK. The parent DS (usually SHA-256) binds the chain. No record means DNSSEC is off, which is valid.

Record Value Note
KSK flags 257 Key Signing Key. Zone + SEP. DS points at this key.
ZSK flags 256 Zone Signing Key. Signs RRSIG. Not in DS.
Alg 13 ECDSAP256SHA256 ECDSA P-256. Short key, common recommendation.
Alg 15 ED25519 Modern and short. Some old resolvers lack support.
Alg 8 RSASHA256 RSA. Still common; the key is longer.
DS digest type 2 SHA-256. Published by the parent (registrar). Missing DS can break the chain.

What are DNSSEC and DNSKEY?

DNSSEC signs zone records. DNSKEY holds the KSK (flag 257, Key Signing Key) and ZSK (256, Zone Signing Key). This tool asks your chosen resolver for DNSKEY and the parent DS. Paste a URL and the host is taken; www is dropped.

No record means DNSSEC is off, which is common and valid. The card shows Off in amber, not as a hard fail. On without DS can be a broken chain: a validating resolver may treat the name as BOGUS.

Examples

KSK
flag 257Bound to the parent DS.
Off
no DNSKEYCommon and valid.

Chips, URLs and resolvers

Chips for .com, .net, .org, .com.tr and others switch the TLD. https://www.example.com/path or example.com:443 is accepted.

Google, Cloudflare, OpenDNS, Quad9, Yandex and Türk Telekom chips pick the UDP/53 resolver. The answer may differ from your ISP cache. The rate limit cuts off frequent clicks.

KSK, ZSK and the DS chain

The KSK signs the ZSK; the ZSK signs A/MX/TXT. The parent DS holds a hash of the KSK (usually SHA-256, digest type 2). DS lives at the registrar; DNSKEY lives on your name servers.

Algorithms 13 (ECDSA P-256) and 15 (ED25519) are short. 8 (RSASHA256) is still common. Older 5/7 SHA-1 algorithms are not recommended. This page does not walk RRSIG; it only lists keys and DS.

Who publishes, how to turn off?

Create DNSKEY in your DNS panel (PowerDNS, BIND, Cloudflare DNS, cPanel). Submit DS to the registrar (or parent zone). Some panels send DS automatically. To disable, remove DS first, wait for TTL, then delete DNSKEY; otherwise the chain breaks.

The query leaves from this Linux host. The result is not a security audit or ISO evidence.

Frequently asked questions

Is DNSSEC required?

No. But if it is on and DS/DNSKEY disagree, the name can fail completely.

Where is DS published?

At the registrar or parent zone. DNSKEY lives on your name servers. Remove DS first when turning DNSSEC off.

Is this a full validator?

No. It lists DNSKEY and DS. It does not walk RRSIG/NSEC; a validating resolver may still say BOGUS.

KSK vs ZSK?

KSK (flag 257) binds to DS; ZSK (256) signs zone records. Rollovers are planned separately.

How do I know DNSSEC is on?

DNSKEY plus parent DS means the chain is built. DNSKEY alone is not enough.

I want to turn DNSSEC off

Remove DS at the registrar first, then DNSKEY. The reverse order can take the name down briefly.

Which algorithm is recommended?

ECDSA P-256 (13) or ED25519 (15) are modern and compact. RSA 2048 is still common.