What we checkDNS hygieneDN-02
DNSSEC
DNSSEC signs your DNS answers so they cannot be forged in transit.
- Area
- DNS hygiene
- Check
- DN-02
- Included
- Free in every scan
What we check
We look for a DS record at your registrar and check whether resolvers report the answer as validated. Informational — it never affects your score.
Why it matters
Without DNSSEC, anyone able to intercept a DNS query can answer it. That redirects your visitors and your mail to a server of their choosing, with nothing on your side to notice.
The attack it prevents is not theoretical — cache poisoning and on-path DNS interception are both routinely used, and neither leaves a trace on your side.
It matters most for mail. A forged MX answer sends your incoming mail to somebody else’s server, and nothing about your own systems changes to indicate it.
How to fix it
- 1
Most registrars enable DNSSEC in one click now.
- 2
If your DNS host and registrar are different, both have to be involved — the host signs, the registrar publishes the DS record.
Common questions
- Why is this informational and not graded?
- Adoption is still low enough that grading it would penalise a large share of well-run domains for something their registrar may not offer.
- Can DNSSEC break my domain?
- A botched key rollover can make your domain unresolvable for validating resolvers. Managed DNSSEC from your provider avoids nearly all of that risk.
- Do I still need it if I use HTTPS?
- They cover different things. HTTPS protects the connection once it is made; DNSSEC protects the answer that decides where the connection goes.
See how your domain does on this check.
All 34 checks, a grade, and the exact fix for anything that isn’t right — in about twenty seconds, no signup.