</> Web Validators

DNSSEC Checker

Whether DNS responses for this domain are cryptographically signed and validated.

This is one independent signal used by the Domain Security Score, and can also be run on its own for any domain.

Based on: RFC 4033 — DNS Security Introduction and Requirements (DNSSEC)

About this validation

Checks whether DNS responses for a domain are cryptographically signed and validated.

Rules reviewed:
Sep 6, 2026

SEOTechTests methodology: Data source: a live DNS lookup performed by SEOTechTests, checking for signed records and successful validation per the DNSSEC standard. Standard: RFC 4033 defines DNSSEC's authentication model.

Standards and vendor-documented behavior can change. This reflects the source as last reviewed above, not a permanent guarantee.

FAQ

What does DNSSEC protect against?

DNSSEC adds cryptographic signatures to DNS responses so a resolver can verify they weren't forged or tampered with in transit -- it protects against DNS spoofing and cache-poisoning attacks that redirect visitors to a different, attacker-controlled server.

Why should a domain use DNSSEC?

Without it, nothing cryptographically prevents a network-level attacker from returning fake DNS answers for a domain, which can be used to intercept traffic or impersonate the site.

Is a domain insecure if DNSSEC is not enabled?

Not necessarily. DNSSEC protects DNS authenticity specifically -- it does not determine whether the website itself is trustworthy, and most of the web still operates without it. It's one layer, not a complete security assessment on its own.

Why is DNSSEC included in Domain Security Score?

It's a standardized, verifiable, and directly checkable DNS-integrity protection, so it fits naturally alongside SPF/DKIM/DMARC as part of the DNS Security group.