DS Lookup

Look up delegation signer records.

Live lookup

A DS (delegation signer) record lives in the parent zone and holds a digest of your key-signing key. It tells validating resolvers that your zone is signed and which key to trust. Without a matching DS, DNSSEC signatures are ignored entirely.

Start a check

Public internet targets only
No account needed for tools

Results

Ready when you are

Enter your details above and run the tool.

How DS Lookup works

What it does

Look up delegation signer records.

What you get

Delegation signer records, key tags and digest values.

Live data sources

The target is sent to a network provider. Results include their source; timeouts and unavailable data are clearly marked.

What if a check cannot finish?

Confirm your input and try again. A timeout, blocked request, or unavailable provider is not proof that a domain is broken. Internet measurements and third-party services have limits.

DS Lookup — frequently asked questions

Where does the DS record come from?

You generate it from your KSK and give it to your registrar, who publishes it in the parent zone. Most DNS providers can hand the values straight to the registrar for you.

What happens if the DS does not match my DNSKEY?

Validating resolvers treat the whole zone as bogus and refuse to resolve it — the domain goes dark for a large share of users. Mismatched DS records are the classic DNSSEC outage.

How do I turn DNSSEC off safely?

Remove the DS record at the registrar first, wait for its TTL to expire everywhere, and only then unsign the zone. Doing it the other way round breaks the domain.