Validate DNSSEC configuration, chain of trust, key algorithms, signature expiry, and NSEC/NSEC3 enumeration protection for any domain.
Validates the complete DNSSEC chain from root zone through TLD to your domain.
Inspects DNSKEY and DS records — algorithms, key strength, KSK/ZSK roles, and security grading.
Checks authenticated denial of existence and zone enumeration protection configuration.