ADVERT
IPSECKEY Record Checker
Check IPSECKEY records that distribute public keys for IPsec security associations and VPN discovery.
How to use this tool
- Query IPSECKEY records for the DNS name used by your VPN or IPsec peers.
- Inspect precedence, gateway, algorithm, key material, and TTL values.
- Verify associated gateway A/AAAA records and client compatibility before rollout.
Key distribution checks
- Validate advertised public keys and gateway references for each peer.
- Confirm precedence behavior when multiple keys are published.
- Use TTL values to plan key rotation timing and verification cycles.
Operational guidance
- Gateway hosts should resolve correctly via A/AAAA records.
- IPSECKEY helps discovery but should align with broader auth policy.
- Prefer frequent credential rotation with monitored propagation windows.
FAQ
- Do IPSECKEY records replace certificates?
- No. They can complement certificate-based systems but do not eliminate the need for policy-driven authentication controls.
- How do precedence values affect clients?
- Lower precedence values are generally preferred, allowing ordered key selection when multiple records exist.
ADVERT
ADVERT