ADVERT
DS Record Checker
Check DS records to confirm DNSSEC delegation between parent and child zones and review key digests.
How to use this tool
- Query DS records at the parent-zone level for the target domain.
- Review key tag, algorithm, digest type, and digest values.
- Compare DS output with child-zone DNSKEY records to validate trust chain continuity.
Delegation validation
- Confirm DS key tags match active DNSKEYs in the child zone.
- Inspect digest types used by your registry and signing policy.
- Use TTL values to estimate parent-zone propagation timing.
Rollover guidance
- Publish new DS entries while old keys remain valid during transition.
- Remove retired DS digests after validators have shifted to new keys.
- Investigate SERVFAIL outcomes for mismatched DS and DNSKEY sets.
FAQ
- What role does a DS record play?
- DS records anchor a child zone DNSKEY set in the parent zone, enabling DNSSEC trust validation.
- Why can multiple DS records exist?
- Multiple DS records are common during key rollover windows so both old and new keys validate.
ADVERT
ADVERT