ToolHop.

ADVERT

DS Record Checker

Check DS records to confirm DNSSEC delegation between parent and child zones and review key digests.

How to use this tool

  1. Query DS records at the parent-zone level for the target domain.
  2. Review key tag, algorithm, digest type, and digest values.
  3. Compare DS output with child-zone DNSKEY records to validate trust chain continuity.

Delegation validation

  • Confirm DS key tags match active DNSKEYs in the child zone.
  • Inspect digest types used by your registry and signing policy.
  • Use TTL values to estimate parent-zone propagation timing.

Rollover guidance

  • Publish new DS entries while old keys remain valid during transition.
  • Remove retired DS digests after validators have shifted to new keys.
  • Investigate SERVFAIL outcomes for mismatched DS and DNSKEY sets.

FAQ

What role does a DS record play?
DS records anchor a child zone DNSKEY set in the parent zone, enabling DNSSEC trust validation.
Why can multiple DS records exist?
Multiple DS records are common during key rollover windows so both old and new keys validate.

ADVERT

ADVERT