← All tools

DNSSEC Chain Inspector

Parse and cross-check pasted DNSSEC resource records entirely in your browser.

Local structural audit only: this tool performs no DNS queries and no RRSIG cryptographic verification. It cannot establish a live chain of trust, delegation correctness, authenticated denial, key revocation state, or resolver behavior. NSEC/NSEC3 checks are observations over the incomplete pasted set.

If blank, the current time is used. DNSSEC inception/expiration fields use UTC YYYYMMDDHHMMSS.

Limits: 1 MiB, 5,000 records, 50,000 tokens, 4,096-byte decoded key/signature fields. Names must be absolute literal ASCII ending in a dot; DNS escapes and zone directives are rejected.

Audit

Parsed records

Parsed DNSSEC records and local linkage observations
#OwnerTTL / classTypeKey/digest/signature metadataLocal linkage