DS Lookup
Read the DS records the parent zone publishes for a domain, decode each one, and verify its digest against the domain's own DNSSEC keys.
How to Read a DS Record
A DS (Delegation Signer) record does not live in the domain's own zone. It is published one level up, in the parent zone, by the registry — which is why you add it through your registrar rather than your DNS host. It is the single link that anchors a signed zone to the chain of trust.
- Key tag
- Short checksum naming which of the domain's DNSKEY records this DS vouches for. It must match a key the domain actually publishes.
- Algorithm
- The signing algorithm of the key being vouched for. ECDSAP256SHA256 (13) and ED25519 (15) are the current recommendations; RSASHA1 (5 and 7) is deprecated.
- Digest type
- Hash used to fingerprint the key. SHA-256 (2) is the standard choice; SHA-1 (1) is deprecated and should be removed once a SHA-256 DS is in place.
- Digest
- The fingerprint itself, taken over the domain name plus the key data. This tool recomputes it from the live DNSKEY record, so a stale DS left behind after a key rotation is caught.
- AD flag
- Authenticated Data. Set when the resolver itself successfully validated the signatures on this answer.
A DS record that matches no published key is worse than no DNSSEC at all: validating resolvers will refuse every answer for the domain instead of falling back to unsigned.
How to use it
- Enter Domain or IP Enter the domain name, IP address, or URL into the Ds Lookup to start the lookup or analysis.
- Run the Check Click the check button to query the relevant databases. Results are retrieved and displayed in seconds.
- Analyze the Results Review the detailed results including status, records, and diagnostics to troubleshoot or verify your query.
Tip Run the Ds Lookup from different times of day to catch intermittent issues that only appear during peak traffic.
Understanding DS Records in DNS
In the Domain Name System (DNS), a Delegation Signer (DS) record plays a crucial role in DNS Security Extensions (DNSSEC). DNSSEC adds a layer of security by enabling DNS responses to be verified for authenticity, preventing attacks like cache poisoning.
A DS record is used to establish a chain of trust between a parent zone and a child zone. It contains a cryptographic hash of the child zone’s DNSKEY record, which holds the public key used to verify DNSSEC signatures. When a resolver queries a domain, it can use the DS record from the parent zone to confirm that the child zone’s DNSKEY is valid and trusted.
Why is this important? Without DS records, DNSSEC validation cannot be completed, leaving domains vulnerable to spoofing and other attacks. DS records ensure that the delegation from one DNS zone to another is secure and that the DNS data has not been tampered with.
Common use cases for DS lookups include:
- Verifying DNSSEC configurations during domain setup or troubleshooting.
- Checking if a domain’s DNS delegation is properly secured.
- Ensuring that DNSKEY records match the DS records published by the parent zone.
What is a DS Record?
A DS (Delegation Signer) record is a special DNS record used in DNSSEC to secure the delegation of a domain from its parent zone. It contains a cryptographic hash of the child zone’s DNSKEY record, which holds the public key for DNSSEC validation. This record helps establish a chain of trust, ensuring that DNS responses are authentic and have not been tampered with.
When to Use a DS Lookup
- To verify that a domain’s DNSSEC delegation is correctly configured by checking the DS record published in the parent zone.
- During domain transfers or DNSSEC key rollovers to ensure the DS records are updated accordingly.
- When troubleshooting DNS resolution issues related to DNSSEC failures or validation errors.
- To confirm that the DNSKEY records of a child zone match the DS records in the parent zone, maintaining the chain of trust.
Common Mistakes to Avoid
- Confusing DS records with DNSKEY or other DNS record types, which serve different purposes.
- Assuming that having a DS record alone guarantees DNSSEC protection without verifying the full chain of trust and DNSKEY validity.
Understanding DS records and performing DS lookups are essential steps in managing DNSSEC-secured domains. They help ensure that your domain’s DNS data is trustworthy and protected against common DNS attacks.
Frequently asked questions
Reviews and questions
Whether this tool gave people the answer they needed, and what they asked about it.
Sign in to review this tool.
No reviews yet
Be the first to say whether this tool gave you what you needed.
Ask how to read the result, or what the tool does with an edge case — or answer someone else.
No questions yet
Not sure how to read a result? Be the first to ask.
AI tools related to this topic
Tools from the TiorAI directory that work on the same kind of job.
Action Network
Action Network is a free digital organizing platform designed for progressive activists and nonprofits to manage petitions, fundraising, email and SMS outreach, and events.
AdEx Network
AdEx Network is a blockchain-powered decentralized advertising platform that ensures transparency, reduces ad fraud, and provides real-time analytics for advertisers and publishers.
AgFunder Network Partners
AgFunder Network Partners is a venture capital platform that connects investors with early-stage agriculture technology startups, providing funding, networking, and market insights to support innovation in agtech.
Joba Network
Joba Network is a decentralized freelance job marketplace built on Ethereum that connects employers and freelancers using smart contracts to ensure secure, transparent transactions and automated escrow payments.
Layla Network AI
Layla Network AI is an AI-driven platform that automates network monitoring, anomaly detection, and troubleshooting to improve network reliability and operational efficiency.