ToolHop.

ADVERT

NSEC Record Checker

Inspect NSEC records to understand how a zone proves the nonexistence of names and reveals covered ranges.

How to use this tool

  1. Query NSEC records for the target zone or name.
  2. Review owner/next-domain pointers and RR type bitmap data.
  3. Use results to validate authenticated denial responses and troubleshoot missing names.

What NSEC reveals

  • Next-domain links that prove nonexistence between signed names.
  • Type bitmaps that indicate which RRsets exist at a node.
  • TTL signals that affect negative caching windows.

Operational guidance

  • Classic NSEC permits zone walking via next-name disclosure.
  • Consider NSEC3 if name enumeration exposure is a concern.
  • Validate canonical ordering and signatures to avoid resolver failures.

FAQ

Why is the type bitmap important?
Validators use the bitmap to confirm which record types exist and to prove specific type nonexistence.
Can NSEC enable zone enumeration?
Yes. Next-name pointers can be traversed to enumerate signed names in classic NSEC zones.
What can cause NSEC validation errors?
Invalid next-name ordering, inconsistent type bitmaps, or broken signatures can all trigger validation failures.

Resources

ADVERT

ADVERT