DMARC Analyzer

DNSSEC check

← All help articles · Health-check results

DNSSEC cryptographically signs DNS responses so a resolver can verify they weren't forged or altered — including the very SPF/DKIM/DMARC records this tool depends on for authentication decisions. This check specifically queries DS records via dig (native PHP DNS functions can't retrieve them), pinned to the resolver configured in healthcheck.resolver.

Absence of DNSSEC is a posture signal, not an active break — most domains today still don't sign their zones, so this is typically reported as info/warn rather than fail.

References