ADVERT
RRSIG Record Checker
View RRSIG records to inspect DNSSEC signatures, inception and expiration windows, and covered record sets.
How to use this tool
- Query RRSIG records for the zone or name under review.
- Inspect covered type, signer, key tag, inception, and expiration windows.
- Correlate signature metadata with DNSKEY and DS records when diagnosing DNSSEC failures.
Signature health checks
- Catch expired or not-yet-valid signatures before they trigger validation failures.
- Verify key tags point to expected active DNSKEY entries.
- Confirm required record sets are being signed by authoritative infrastructure.
Operational guidance
- Keep signer clocks synchronized to avoid future-dated signatures.
- Use practical validity windows that balance risk and operational load.
- Audit signature coverage after dynamic updates or key rollovers.
FAQ
- Why can inception times appear in the future?
- Clock skew on signing infrastructure can produce signatures that are not yet valid to resolvers.
- What if an RRSIG covers NSEC or NSEC3 records?
- That is expected in DNSSEC zones and protects authenticated denial-of-existence responses.
- How long should RRSIG validity windows be?
- Many operators use moderate windows and rotate regularly to balance resilience with compromise exposure.
ADVERT
ADVERT