DNSlens

DNSSEC checker

A signed zone is only protected if the parent points at the right key and every signature still verifies. The check that settles it is asking the resolver twice — once letting it validate, once telling it not to.

The verdict comes from asking twice: once letting the resolver validate, once telling it not to. A name that answers only with checking disabled is one the resolver rejected.

Try one of these