DNSKEY Lookup

Inspect the public keys used by DNSSEC.

Live lookup

DNSKEY records hold the public keys a signed zone uses for DNSSEC. A DNSKEY lookup returns those keys with their flags — 257 marks a key-signing key, 256 a zone-signing key — and the algorithm each one uses.

Start a check

Public internet targets only
No account needed for tools

Results

Ready when you are

Enter your details above and run the tool.

How DNSKEY Lookup works

What it does

Inspect the public keys used by DNSSEC.

What you get

DNSSEC public key records, flags and algorithm identifiers.

Live data sources

The target is sent to a network provider. Results include their source; timeouts and unavailable data are clearly marked.

What if a check cannot finish?

Confirm your input and try again. A timeout, blocked request, or unavailable provider is not proof that a domain is broken. Internet measurements and third-party services have limits.

DNSKEY Lookup — frequently asked questions

What is the difference between flag 256 and 257?

257 is the key-signing key (KSK), which the parent zone's DS record points at. 256 is the zone-signing key (ZSK), which signs the actual records. The KSK signs the ZSK.

No DNSKEY records came back. Is that a problem?

Only if you expected DNSSEC. An unsigned zone has no DNSKEY records, and most domains are unsigned. It is not an error.

Does having DNSKEY records mean DNSSEC works?

Not on its own. The parent zone also needs a matching DS record. Keys without a DS are published but never validated — check the DS lookup too.