DNSSEC, drawn live
The chain of trust, drawn from live answers
Type a signed domain. Your browser asks cloudflare-dns.com for the DNSKEY
and DS set at every label, root to leaf, and draws every key, DS, and signature that comes
back. It is one recursive answering per cut, not a referral walk from the root servers.
Hover or tap any box for the live values. Fetched live, not canned.
try
vantage: your browser → cloudflare-dns.com (1.1.1.1) over DoH, JSON API
verified relation
not verifiable from client data
mismatch or out of validity
flags: DO + CD ride the query (client side), AD comes back in the response (the resolver's verdict) · lime = 1, dim = 0
hover a box or an edge for the evidence
×
How we walked it
What this page verifies in your browser, and what it does not.
- Computed here: key tags from each DNSKEY's rdata (RFC 4034 appendix B), DS digests recomputed with WebCrypto (SHA-1/256/384) and compared byte for byte against the parent's DS, and every RRSIG inception/expiration window checked against your clock.
- Not computed here: the signature bytes themselves. Verifying an RRSIG needs the canonical wire form of the whole RRset; this page does not do that math. Where a relation rests on the signature alone it is drawn dashed amber, and the resolver's AD (authenticated data) flag is shown as the validating resolver's own verdict.
- The root key is a trust anchor. The root DNSKEY RRset shown is fetched live, but trust in it comes from resolver configuration, not from this page. We do not fetch the IANA anchor file here.
- A different vantage can see a different chain mid-rollover. This one is your browser's.
more: DNSViz · dnssec: /wiki/security/dnssec · less: /tldr-dnssec