DNSKEY Lookup
Inspect the public keys used by DNSSEC.
DNSKEY records hold the public keys a signed zone uses for DNSSEC. A DNSKEY lookup returns those keys with their flags — 257 marks a key-signing key, 256 a zone-signing key — and the algorithm each one uses.
Start a check
Public internet targets onlyResults
Ready when you are
Enter your details above and run the tool.
How DNSKEY Lookup works
What it does
Inspect the public keys used by DNSSEC.
What you get
DNSSEC public key records, flags and algorithm identifiers.
Live data sources
The target is sent to a network provider. Results include their source; timeouts and unavailable data are clearly marked.
What if a check cannot finish?
Confirm your input and try again. A timeout, blocked request, or unavailable provider is not proof that a domain is broken. Internet measurements and third-party services have limits.
DNSKEY Lookup — frequently asked questions
What is the difference between flag 256 and 257?
257 is the key-signing key (KSK), which the parent zone's DS record points at. 256 is the zone-signing key (ZSK), which signs the actual records. The KSK signs the ZSK.
No DNSKEY records came back. Is that a problem?
Only if you expected DNSSEC. An unsigned zone has no DNSKEY records, and most domains are unsigned. It is not an error.
Does having DNSKEY records mean DNSSEC works?
Not on its own. The parent zone also needs a matching DS record. Keys without a DS are published but never validated — check the DS lookup too.