DNSSEC analyzer
Walks the trust chain from root to leaf, validates every signature.
DNSSEC: SIGNED
Chain data found for github.com
Demo chain preview
DS / DNSKEY data available
Chain of trust
Each step's DS hash must match the child's DNSKEY. All signatures must validate.
Root zone (.)
.com TLD
github.com → DNSKEY
github.com → RRSIG (A, MX, TXT...)
NSEC3 denial-of-existence
DS records
2
DNSKEY records
3
RRSIG records
11
Sig expires
6d 14h