ADVERT
DNSKEY Record Checker
Retrieve DNSKEY records published for DNSSEC validation, including algorithms, key tags, and public keys.
How to use this tool
- Query DNSKEY records for the zone you want to validate.
- Review key tags, algorithms, flags, and public key material.
- Cross-check DNSKEY entries against DS and RRSIG data during rollovers.
DNSSEC key checks
- Flag 257 generally indicates KSK, while 256 indicates ZSK.
- Use key tags to match DNSKEY records with DS and RRSIG references.
- Verify replacement keys are visible before retiring older keys.
Operational guidance
- Stage rollover keys early so validating resolvers can cache them.
- Confirm parent-zone DS updates align with published DNSKEYs.
- Audit keysets after signer changes to catch propagation gaps.
FAQ
- What is the purpose of the key tag?
- The key tag is a compact identifier used to associate DNSKEY records with DS entries and signatures.
- Why might several DNSKEY records be present?
- Zones commonly publish multiple keys during planned KSK or ZSK rollovers.
ADVERT
ADVERT