Skip to content

What we checkDNS hygieneDN-02

DNSSEC

DNSSEC signs your DNS answers so they cannot be forged in transit.

Check
DN-02
Included
Free in every scan

What we check

We look for a DS record at your registrar and check whether resolvers report the answer as validated. Informational — it never affects your score.

Why it matters

Without DNSSEC, anyone able to intercept a DNS query can answer it. That redirects your visitors and your mail to a server of their choosing, with nothing on your side to notice.

The attack it prevents is not theoretical — cache poisoning and on-path DNS interception are both routinely used, and neither leaves a trace on your side.

It matters most for mail. A forged MX answer sends your incoming mail to somebody else’s server, and nothing about your own systems changes to indicate it.

How to fix it

  1. 1

    Most registrars enable DNSSEC in one click now.

  2. 2

    If your DNS host and registrar are different, both have to be involved — the host signs, the registrar publishes the DS record.

Common questions

Why is this informational and not graded?
Adoption is still low enough that grading it would penalise a large share of well-run domains for something their registrar may not offer.
Can DNSSEC break my domain?
A botched key rollover can make your domain unresolvable for validating resolvers. Managed DNSSEC from your provider avoids nearly all of that risk.
Do I still need it if I use HTTPS?
They cover different things. HTTPS protects the connection once it is made; DNSSEC protects the answer that decides where the connection goes.

See how your domain does on this check.

All 34 checks, a grade, and the exact fix for anything that isn’t right — in about twenty seconds, no signup.