DNS & Domain
Open DNS Health & DNSSEC →Start with the exact hostname
A website hostname and its zone apex may differ. Check the name visitors actually use, including www when applicable. A and AAAA responses concern address resolution; an NXDOMAIN response can also originate from a missing CNAME target. A name without website addresses may still be valid for email or other services.
Understand what DNSSEC validation establishes
DNSSEC lets a validating resolver authenticate signed DNS data through a chain of trust. This tool reports the resolver’s AD flag over HTTPS; it does not perform its own cryptographic validation. An authenticated negative response can prove that a record is absent. DNSSEC does not encrypt DNS contents or verify website TLS certificates.
Investigate SERVFAIL without guessing
SERVFAIL can arise from DNSSEC or other resolver and authoritative-server problems. If a validating address query fails but the same resolver returns addresses with checking disabled, a validation problem is suspected. The unchecked data is diagnostic evidence, not trusted data or an instruction to turn off DNSSEC.
Compare publication with validation
The tool uses an observed SOA owner to identify the enclosing zone, rather than assuming every domain has two labels. It then queries that zone’s NS, DS and DNSKEY records. Their presence alone does not prove that a DS digest matches a key. During a provider migration, compare the registrar’s DS with the provider’s current DNSKEY information and follow their coordinated rollover procedure.
Know the boundaries of this check
Cloudflare and Google are recursive services queried from the current VPS. This is not global propagation measurement, a direct nameserver reachability test, a glue audit or a comparison of parent and child delegation. When either resolver is unavailable, preserve that uncertainty and repeat the check before changing configuration.
Worked example
Illustrative output — not a live test A with validation: SERVFAIL A with checking disabled: 192.0.2.10 Assessment: DNSSEC validation problem suspected Next: compare registrar DS and provider keys; inspect signatures Do not treat the unchecked address as authenticated.
What to check next
- Open DNS Health & DNSSEC with the exact hostname.
- Compare both resolvers and expand the raw evidence for response codes and AD/CD flags.
- Check the registrar nameserver and DS configuration against the DNS provider’s settings.
- After a coordinated correction and relevant cache expiry, repeat validating lookups.
- Run HTTP Status and SSL Certificate separately to verify the website.