DNSSEC validator

Validating resolver

Check whether a DNS response authenticates through DNSSEC, is intentionally unsigned, fails validation, or cannot be classified.

Queries use Cloudflare's DNSSEC-validating resolver with five-second deadlines and a five-minute result cache.

Enter a DNS name to inspectThe result separates an unsigned chain from a broken chain and from an inconclusive resolver failure.

How the four states differ

Secure means the validating resolver authenticated the response. Insecure means it completed normally without an authenticated chain, usually because the zone is unsigned or deliberately delegated as insecure.

Bogus is reported only when validation returns SERVFAIL but the same question succeeds with checking disabled. Indeterminate covers timeouts, provider failures, and SERVFAIL responses that cannot be isolated to DNSSEC.