ADVERT
NSEC Record Checker
Inspect NSEC records to understand how a zone proves the nonexistence of names and reveals covered ranges.
How to use this tool
- Query NSEC records for the target zone or name.
- Review owner/next-domain pointers and RR type bitmap data.
- Use results to validate authenticated denial responses and troubleshoot missing names.
What NSEC reveals
- Next-domain links that prove nonexistence between signed names.
- Type bitmaps that indicate which RRsets exist at a node.
- TTL signals that affect negative caching windows.
Operational guidance
- Classic NSEC permits zone walking via next-name disclosure.
- Consider NSEC3 if name enumeration exposure is a concern.
- Validate canonical ordering and signatures to avoid resolver failures.
FAQ
- Why is the type bitmap important?
- Validators use the bitmap to confirm which record types exist and to prove specific type nonexistence.
- Can NSEC enable zone enumeration?
- Yes. Next-name pointers can be traversed to enumerate signed names in classic NSEC zones.
- What can cause NSEC validation errors?
- Invalid next-name ordering, inconsistent type bitmaps, or broken signatures can all trigger validation failures.
Resources
ADVERT
ADVERT