Check the DS (delegation signer) records a domain has at its parent zone, with key tag, algorithm and digest type, to confirm DNSSEC is linked.
About this tool
Check the DS (delegation signer) records that link a domain to DNSSEC at its parent zone.
How to use DS Record Lookup
- Enter the domain name, such as example.com.
- Click Find DS records.
- Compare the key tag and algorithm with the domain’s DNSKEY records; they must match for DNSSEC to validate.
Worked example
If your DNS host shows DNSSEC as “on” but the DS lookup finds nothing, copy the DS details from the DNS host into your registrar’s DNSSEC settings.
Where does the DS record live?
In the parent zone, such as .com for example.com. You add it at your registrar, which passes it to the registry.
Which digest type should I use?
SHA-256 (digest type 2) is the recommended choice today. SHA-1 (type 1) is outdated.
- DS Record Lookup — Check the DS (delegation signer) records that link a domain to DNSSEC at its parent zone.
Explore DNS Tools · More practical guides