Skip to content

How to Use DNSKEY Lookup

Look up the DNSKEY records of a DNSSEC-signed domain and see each key’s role (KSK or ZSK), key tag, algorithm and whether answers validate.

About this tool

Look up a domain's DNSSEC public keys (DNSKEY records) with flags, algorithm and key tag.

How to use DNSKEY Lookup

  1. Enter a domain name that you expect to be signed with DNSSEC.
  2. Click Find DNSKEY.
  3. Read the key list and the validation badge. The key tag of the KSK should match a DS record at the parent zone.

Worked example

cloudflare.com publishes a KSK with key tag 2371 and a ZSK, both using algorithm 13 (ECDSA P-256). Its DS record in .com also has key tag 2371, completing the chain of trust.

What is the difference between a KSK and a ZSK?

The key signing key (flag 257) signs the set of keys, and the zone signing key (flag 256) signs the other records. Splitting them makes routine key changes easier.

What is a key tag?

A short number calculated from the key data that lets resolvers quickly match a DS record or signature to the right key.

Put this guide into practice

  • DNSKEY Lookup — Look up a domain's DNSSEC public keys (DNSKEY records) with flags, algorithm and key tag.

Explore DNS Tools · More practical guides

Accessibility Menu

Personalize your experience. Open with Ctrl+U (Option+U on Mac). Preferences stay in this browser when storage is available.

Move / Hide Widget

Restore at any time with Ctrl+U (Option+U on Mac).

Accessibility statement and help