Skip to content

DNSKEY Lookup

Look up a domain's DNSSEC public keys (DNSKEY records) with flags, algorithm and key tag.

Enter a DNSSEC-signed domain such as cloudflare.com or ietf.org.

Continue your work

Share this tool

Found it useful? Send it to a friend or teammate.

Rate this tool

0.0

0 ratings

  • 5 stars 0
  • 4 stars 0
  • 3 stars 0
  • 2 stars 0
  • 1 star 0

Click a star to rate this tool

Clear instructions

Find steps, examples and limitations below.

Use online

Open the tool in a supported web browser.

Free to use

No sign-up required. Tool-specific limits may apply.

How to use the DNSKEY Lookup

Look up a domain's DNSSEC public keys (DNSKEY records) with flags, algorithm and key tag.

  1. 1 Enter a domain name that you expect to be signed with DNSSEC.
  2. 2 Click Find DNSKEY.
  3. 3 Read the key list and the validation badge. The key tag of the KSK should match a DS record at the parent zone.

Example and practical tips

cloudflare.com publishes a KSK with key tag 2371 and a ZSK, both using algorithm 13 (ECDSA P-256). Its DS record in .com also has key tag 2371, completing the chain of trust.

Frequently asked questions

What is the difference between a KSK and a ZSK?

The key signing key (flag 257) signs the set of keys, and the zone signing key (flag 256) signs the other records. Splitting them makes routine key changes easier.

What is a key tag?

A short number calculated from the key data that lets resolvers quickly match a DS record or signature to the right key.

Report an issue

Something broken or not quite right? Tell us and we will look into it.