DNSSEC Check: Professional DNS Security and Validation ToolPerform deep
trust-chain validation, cryptographic audits, and standards-compliant reporting for any domain — all powered by the
CyprNet Secure TrustPath Engine. This is the essential
DNSSEC analysis tool for network and
security professionals.
— End-to-End DNSSEC Analysis —
- Parent → child zone validation with authoritative-direct probing (DO=1, UDP 1232, TCP fallback)
- Operates through corporate recursive resolvers when direct probing is restricted
- DS ↔ DNSKEY mapping with match coverage
- SHA-1 detection and crypto-grade scoring
- RFC 8078 support: detect CDS/CDNSKEY for automated trust-anchor updates
- Unified TrustReport model powering UI and HTML reports
— Free (Analysis) Experience —
- Trust Chain Integrity: compact DS↔DNSKEY summary, parent zone info, match counts
- Cryptographic Profile: SHA-1 cap indicator; DNSKEY algorithm list
- Coverage of Signed RRsets: overall % from scoring
- Pro features previewed with six distinct cards (headline metric visible; details blurred)
— Pro Capabilities (Full Toolset) —The Pro version unlocks the full suite of
DNSSEC security features, including:
- Delegation (CDS/CDNSKEY): presence detection, counts, TTL; guidance when missing (RFC 5011)
- Parent ↔ Child Linkage: DS digest ↔ DNSKEY tag mapping, SHA-1 warnings, copyable records
- Key Audit: algorithm distribution, KSK/ZSK counts, earliest/median RRSIG expiry
- Coverage: SOA, NS, DNSKEY, apex A/AAAA, MX coverage of Signed RRsets
- Mobile-First HTML Report: Professional, sortable, and shareable reports with findings and artifacts
- Findings & Recommendations: Critical / Warning / Info; items link to report anchors
— Vantage Modes —
- Authoritative-Direct: probes authoritative NS (RD=0, DO=1) with TCP fallback
- Corporate-Recursive: labels resolvers; shows samples and capabilities; notes limitations
Built by CyprNet Solutions — Trusted tools for network and
security professionals.
Analyze. Validate. Trust.