ToolHop.

ADVERT

IPSECKEY Record Checker

Check IPSECKEY records that distribute public keys for IPsec security associations and VPN discovery.

How to use this tool

  1. Query IPSECKEY records for the DNS name used by your VPN or IPsec peers.
  2. Inspect precedence, gateway, algorithm, key material, and TTL values.
  3. Verify associated gateway A/AAAA records and client compatibility before rollout.

Key distribution checks

  • Validate advertised public keys and gateway references for each peer.
  • Confirm precedence behavior when multiple keys are published.
  • Use TTL values to plan key rotation timing and verification cycles.

Operational guidance

  • Gateway hosts should resolve correctly via A/AAAA records.
  • IPSECKEY helps discovery but should align with broader auth policy.
  • Prefer frequent credential rotation with monitored propagation windows.

FAQ

Do IPSECKEY records replace certificates?
No. They can complement certificate-based systems but do not eliminate the need for policy-driven authentication controls.
How do precedence values affect clients?
Lower precedence values are generally preferred, allowing ordered key selection when multiple records exist.

ADVERT

ADVERT