DNSSEC chain: how far does it reach, and where does it break?

Enter a domain and we walk the chain of trust from the root zone down to the domain's own zone: for every zone we show its keys, the DS records its parent holds, and whether the two belong together.

What the DNSSEC chain shows

The zones in order
The root, the top-level domain (for example .hu) and the domain's own zone, each vouching for the next.
DS records
The digest of the child zone's key, kept in the parent zone. The tool recomputes the digest and shows whether it really belongs to a published key.
Keys
The zone's key-signing (KSK) and zone-signing (ZSK) keys, with their algorithm and, for RSA, their length. Outdated algorithms are flagged.
Signature
Whether the key set is signed and until when the signature is valid. An expired signature is the most common reason a domain suddenly stops resolving.
The resolver's verdict
What a validating resolver says: whether it accepts the answer as authentic or refuses the domain.

Frequently asked questions

What is DNSSEC?

DNSSEC adds digital signatures to DNS answers, so a resolver can check that an answer really comes from the domain's nameserver and was not forged on the way. The protection is a chain: the root vouches for .hu, and .hu vouches for your domain.

Why did my domain stop working after I enabled DNSSEC?

Almost always because the DS record at the registrar does not belong to the zone's current key, for example after a change of nameservers or keys. Validating resolvers then refuse every answer. The chain shows at which zone the mismatch is.

My zone is signed, yet it says "not protected". Why?

Because the parent zone has no DS record. Signing alone is not enough: the key's digest has to reach the parent zone through the registrar, and only that makes the chain continuous.

I am changing nameservers. What should I watch out for?

If the domain is protected by DNSSEC, have the DS record removed at the registrar first, wait for that to take effect, and only then change the nameservers. You can enable DNSSEC again at the new provider.

Have a question about the results, or need help fixing something? Contact our support