What are DNSSEC and DNSKEY?
DNSSEC signs zone records. DNSKEY holds the KSK (flag 257, Key Signing Key) and ZSK (256, Zone Signing Key). This tool asks your chosen resolver for DNSKEY and the parent DS. Paste a URL and the host is taken; www is dropped.
No record means DNSSEC is off, which is common and valid. The card shows Off in amber, not as a hard fail. On without DS can be a broken chain: a validating resolver may treat the name as BOGUS.
Examples
- KSK
flag 257Bound to the parent DS.- Off
no DNSKEYCommon and valid.
Chips, URLs and resolvers
Chips for .com, .net, .org, .com.tr and others switch the TLD. https://www.example.com/path or example.com:443 is accepted.
Google, Cloudflare, OpenDNS, Quad9, Yandex and Türk Telekom chips pick the UDP/53 resolver. The answer may differ from your ISP cache. The rate limit cuts off frequent clicks.
KSK, ZSK and the DS chain
The KSK signs the ZSK; the ZSK signs A/MX/TXT. The parent DS holds a hash of the KSK (usually SHA-256, digest type 2). DS lives at the registrar; DNSKEY lives on your name servers.
Algorithms 13 (ECDSA P-256) and 15 (ED25519) are short. 8 (RSASHA256) is still common. Older 5/7 SHA-1 algorithms are not recommended. This page does not walk RRSIG; it only lists keys and DS.
Who publishes, how to turn off?
Create DNSKEY in your DNS panel (PowerDNS, BIND, Cloudflare DNS, cPanel). Submit DS to the registrar (or parent zone). Some panels send DS automatically. To disable, remove DS first, wait for TTL, then delete DNSKEY; otherwise the chain breaks.
The query leaves from this Linux host. The result is not a security audit or ISO evidence.