DNSSEC of raypal.com.
Check whether DNSSEC protects a domain and, when it fails, exactly where the chain breaks.
Looking up…
How the chain of trust works.
- The registry of the extension holds a DS record for the domain: a digest of the domain's key-signing key. You set it at your registrar.
- The domain's DNS host publishes that key-signing key, which signs the zone-signing key, which signs every record.
- A validating resolver follows the chain from the root down. If any link fails, it refuses to answer rather than risk a forged reply.
Secure, not signed, failing.
- Secure: the chain holds and answers are protected.
- Not signed: no DS record at the registry. Answers are trusted as they come, like most domains on the internet.
- Failing (bogus): there is a DS record, but the keys or signatures do not match it. Validating resolvers return SERVFAIL, so the domain is offline for their users.
Turning DNSSEC on.
Switch signing on at your DNS host, which then shows a DS record (key tag, algorithm, digest). Add that DS record at your registrar. Within the registry's TTL, this page should show the chain as secure.
Moving DNS hosts without an outage.
Before you change name servers, remove the DS record at the registrar and wait a day, or follow your new host's guide for moving a signed zone. Changing name servers while the old DS record stays is the most common way domains break under DNSSEC.
Questions people ask.
What is DNSSEC?
Signatures on DNS records that let resolvers check an answer really comes from the domain's DNS host and was not changed on the way. The registry vouches for the domain's key through a DS record.
How do I check if DNSSEC is enabled?
Type the domain. The checker reads the DS record at the registry and the keys in the zone, recomputes the DS digest from the key, and shows whether validating resolvers trust the answers.
Why did my domain stop working after I changed DNS hosts?
If DNSSEC was on, the registry still holds a DS record for the old host's key, so validating resolvers refuse the domain. Remove the DS record at your registrar, or replace it with the new host's.
Should I turn on DNSSEC?
It protects against forged DNS answers and is free at most DNS hosts. The risk is breaking the domain when you move hosts without updating the DS record, so plan moves carefully.
Hivex index
Short names, still free to register.
Starting something new? Hivex keeps a live index of short, brandable .si names nobody has claimed yet, each checked with the registry.
From code, or an AI assistant.
The same lookup is a free JSON API, with no key and open CORS, and a tool any AI assistant that speaks MCP can call.
curl "https://hivex.si/api/v1/tools/dns?name=raypal.com&type=DNSKEY"More DNS tools
- DNS lookupAll records at once: A, AAAA, CNAME, MX, NS, TXT, CAA, SOA.
- MX lookupMail servers in priority order, the provider, SPF and DMARC at a glance.
- NS lookupName servers, the DNS host, SOA settings, and marketplace parking.
- TXT lookupSPF, DMARC, DKIM and verification tokens, joined and labelled.
- CNAME lookupThe full alias chain, the final addresses, and the platform behind it.
- CAA lookupAllowed certificate authorities, wildcard rules and report addresses.
- DNS propagation checker13 public resolvers side by side, with how long each keeps its copy.
- Reverse DNSThe PTR hostname of an IPv4 or IPv6 address, checked both ways.
- DNS health checkEvery name server asked directly: one report, every check.
- Subdomain finderSubdomains from certificate logs, DNS and the archive.
- DNS historyPast IP addresses and hosts, from passive DNS.
- DNS setup helperThe records each platform asks for, checked live.
- Domain checkerIs a name free to register? Checked live on any extension.
Sources
- RFC 4033: DNS Security introduction and requirements
- RFC 4034: Resource records for the DNS security extensions (key tags, DS digests)
- RFC 4035: Protocol modifications for the DNS security extensions
- RFC 8624: Algorithm implementation requirements for DNSSEC
- RFC 8914: Extended DNS errors
By Hivex. Updated 10 October 2026. Lookups run live through Cloudflare's public resolver and are kept for at most five minutes.