DNS Health & DNSSEC

Inspect A, AAAA, zone nameservers, DS and DNSKEY records with Cloudflare and Google DNSSEC validation observations. Understand failures and next steps.

How to use DNS Health & DNSSEC

Enter a domain or hostname, such as example.com. The check queries Cloudflare and Google over HTTPS from the current VPS; it does not connect to returned IP addresses.

Understanding the results

Review A/AAAA responses, resolver-reported DNSSEC validation, and the enclosing SOA zone’s NS, DS and DNSKEY records. A retry with checking disabled is evidence only, never a recommendation to disable DNSSEC. Parent/child delegation agreement, glue and direct authoritative-server reachability are not tested.

Does SERVFAIL always mean DNSSEC is broken?

No. DNS server failures and transport problems can also cause SERVFAIL. Addresses appearing only with checking disabled suggest a validation problem, but do not identify the broken key or signature.

Is a missing DS record a website outage?

No. Unsigned domains can resolve and serve HTTPS. DNSSEC authentication and website availability are separate checks.

Does this check global DNS propagation?

No. It compares observations from two recursive resolver services requested by this VPS. These services may answer from different locations; this is not a set of regional probes.