ToolHop.

ADVERT

RRSIG Record Checker

View RRSIG records to inspect DNSSEC signatures, inception and expiration windows, and covered record sets.

How to use this tool

  1. Query RRSIG records for the zone or name under review.
  2. Inspect covered type, signer, key tag, inception, and expiration windows.
  3. Correlate signature metadata with DNSKEY and DS records when diagnosing DNSSEC failures.

Signature health checks

  • Catch expired or not-yet-valid signatures before they trigger validation failures.
  • Verify key tags point to expected active DNSKEY entries.
  • Confirm required record sets are being signed by authoritative infrastructure.

Operational guidance

  • Keep signer clocks synchronized to avoid future-dated signatures.
  • Use practical validity windows that balance risk and operational load.
  • Audit signature coverage after dynamic updates or key rollovers.

FAQ

Why can inception times appear in the future?
Clock skew on signing infrastructure can produce signatures that are not yet valid to resolvers.
What if an RRSIG covers NSEC or NSEC3 records?
That is expected in DNSSEC zones and protects authenticated denial-of-existence responses.
How long should RRSIG validity windows be?
Many operators use moderate windows and rotate regularly to balance resilience with compromise exposure.

ADVERT

ADVERT