Network Diagnostics and More
Tool guide limitationsGuides explain the intended workflow but cannot cover every device, provider or operating condition.

Interfaces and external services can change. Follow the current on-screen controls, check dates and vendor documentation, and verify important results independently before acting on them.

Important: Do not rely on this result alone for purchasing, configuration, security, safety, compliance, contractual or fault-diagnosis decisions. Results can be incomplete, delayed, misleading or wrong. Verify important findings with the relevant provider, manufacturer documentation and an appropriate independent test or qualified professional.

← All tool guides

DNS and email

DNSSEC & DANE guide

Review DNSSEC chain evidence, DS matching and published TLSA records.

Open DNSSEC & DANE

What you need

  • Public domain or TLSA owner name

How to use it

  1. 1Enter the public name.
  2. 2Run the DNSSEC and DANE check.
  3. 3Review resolver validation and digest evidence.
  4. 4Inspect each TLSA record in context.

Understanding the results

  • An authenticated chain requires consistent parent DS and child DNSKEY evidence.

Recommended next actions

  • Follow the DNS provider's rollover process and verify from another validating resolver.

Common problems

  • Stale DS records and rollover timing can break validation.

Privacy and security

  • Only public lookup data is requested. Avoid entering internal names, credentials or confidential notes.

Worked example

Scenario
Checking a signed mail domain
Example input
example.com
How to read it
Matching DS/DNSKEY evidence supports the chain; TLSA records still need certificate-lifecycle review.

Limitations

  • Some TLSA selectors cannot be byte-matched in the hosted runtime.

Do not rely on one result for a production, security, safety, purchasing or contractual decision. Verify important findings independently.