Skip to content
Hivex tools · DNSFree · No account

DNSSEC of jobs.wikipedia.org.

Check whether DNSSEC protects a domain and, when it fails, exactly where the chain breaks.

Looking up…

How the chain of trust works.

  • The registry of the extension holds a DS record for the domain: a digest of the domain's key-signing key. You set it at your registrar.
  • The domain's DNS host publishes that key-signing key, which signs the zone-signing key, which signs every record.
  • A validating resolver follows the chain from the root down. If any link fails, it refuses to answer rather than risk a forged reply.

Secure, not signed, failing.

  • Secure: the chain holds and answers are protected.
  • Not signed: no DS record at the registry. Answers are trusted as they come, like most domains on the internet.
  • Failing (bogus): there is a DS record, but the keys or signatures do not match it. Validating resolvers return SERVFAIL, so the domain is offline for their users.

Turning DNSSEC on.

Switch signing on at your DNS host, which then shows a DS record (key tag, algorithm, digest). Add that DS record at your registrar. Within the registry's TTL, this page should show the chain as secure.

Moving DNS hosts without an outage.

Before you change name servers, remove the DS record at the registrar and wait a day, or follow your new host's guide for moving a signed zone. Changing name servers while the old DS record stays is the most common way domains break under DNSSEC.

Questions people ask.

What is DNSSEC?

Signatures on DNS records that let resolvers check an answer really comes from the domain's DNS host and was not changed on the way. The registry vouches for the domain's key through a DS record.

How do I check if DNSSEC is enabled?

Type the domain. The checker reads the DS record at the registry and the keys in the zone, recomputes the DS digest from the key, and shows whether validating resolvers trust the answers.

Why did my domain stop working after I changed DNS hosts?

If DNSSEC was on, the registry still holds a DS record for the old host's key, so validating resolvers refuse the domain. Remove the DS record at your registrar, or replace it with the new host's.

Should I turn on DNSSEC?

It protects against forged DNS answers and is free at most DNS hosts. The risk is breaking the domain when you move hosts without updating the DS record, so plan moves carefully.

Hivex index

Short names, still free to register.

Starting something new? Hivex keeps a live index of short, brandable .si names nobody has claimed yet, each checked with the registry.

Browse free names

From code, or an AI assistant.

The same lookup is a free JSON API, with no key and open CORS, and a tool any AI assistant that speaks MCP can call.

curl "https://hivex.si/api/v1/tools/dns?name=jobs.wikipedia.org&type=DNSKEY"

The API guideThe MCP tool dns_lookupOpenAPI schema