ToolHop.

ADVERT

DNSKEY Record Checker

Retrieve DNSKEY records published for DNSSEC validation, including algorithms, key tags, and public keys.

How to use this tool

  1. Query DNSKEY records for the zone you want to validate.
  2. Review key tags, algorithms, flags, and public key material.
  3. Cross-check DNSKEY entries against DS and RRSIG data during rollovers.

DNSSEC key checks

  • Flag 257 generally indicates KSK, while 256 indicates ZSK.
  • Use key tags to match DNSKEY records with DS and RRSIG references.
  • Verify replacement keys are visible before retiring older keys.

Operational guidance

  • Stage rollover keys early so validating resolvers can cache them.
  • Confirm parent-zone DS updates align with published DNSKEYs.
  • Audit keysets after signer changes to catch propagation gaps.

FAQ

What is the purpose of the key tag?
The key tag is a compact identifier used to associate DNSKEY records with DS entries and signatures.
Why might several DNSKEY records be present?
Zones commonly publish multiple keys during planned KSK or ZSK rollovers.

ADVERT

ADVERT