DNSSEC Checker API

GET

Catch broken DNSSEC setups before domains stop resolving.

DNSSEC Checker validates the DNSSEC (Domain Name System Security Extensions) configuration of a domain. It verifies that DNS responses are authenticated and haven't been tampered with.

Try it — live request, no key required

Request
GETapi.apiverve.com/v1/dnsseccheck?domain=cloudflare.com
Query parameters
Verification
Format

No key required to try it. Get a key to use it in your app.

Example
{
  "status": "ok",
  "error": null,
  "data": {
    "domain": "cloudflare.com",
    "dnssecEnabled": true,
    "valid": true,
    "records": {
      "dnskey": 2,
      "ds": 1,
      "nsec": 1
    },
    "errors": [],
    "details": {
      "dnskeyCount": 2,
      "dsCount": 1
    },
    "status": "DNSSEC is properly configured with DS records at parent",
    "recommendation": "DNSSEC is properly configured",
    "riskScore": 5,
    "riskLevel": "low"
  }
}

About the DNSSEC Checker API

DNSSEC Checker works by querying DNSKEY, DS, and RRSIG records for a domain and validating the cryptographic chain of trust. It identifies whether DNSSEC is properly configured, highlights any validation errors, and derives a deployment-health risk score that distinguishes an unhardened domain from one with a broken chain of trust.

What people use it for

Security Auditing
Verify that domains have properly configured DNSSEC to prevent DNS spoofing and cache poisoning attacks
Compliance Checking
Ensure domains meet security compliance requirements that mandate DNSSEC
Domain Monitoring
Monitor DNSSEC status and get alerts if configuration becomes invalid
Troubleshooting
Diagnose DNSSEC validation failures and identify misconfigured records

Ways to call it

One endpoint, many ways in — REST with JSON, XML, YAML and CSV, plus GraphQL and an MCP interface for AI agents.

JSON
Default REST response
XML
Markup format
YAML
Human-readable
CSV
Tabular export
Beta
GraphQL
Query language
New
MCP
For AI agents

How it compares

Side by side with the tools people weigh DNSSEC Checker against — what each one is better at, in plain terms.

Other ways to use DNSSEC Checker

Same data, same APIVerve account, same credit balance — one key works on all of them.

Questions.

Common questions about the DNSSEC Checker API.

Read the docs →
What records does the validation check?
It queries DNSKEY, DS, and RRSIG records to verify the domain's cryptographic chain of trust. The check also inspects parent DS records, zone DNSKEY counts, and any NSEC or NSEC3 records used to prove authenticated non-existence.
What happens if a domain has not configured DNSSEC at all?
The response reports that DNSSEC is not enabled, and the errors array remains empty because an unconfigured domain is not treated as a broken signature chain. On paid plans, DNSSEC Checker uses its deployment health risk score to separate an unhardened domain from one suffering from validation failures.
Do I get the deployment risk score and record breakdown on the Free plan?
No. The Free plan returns validation status, basic errors, and recommendations. Access to the composite risk score, risk level band, and detailed DNSKEY, DS, and NSEC record structures requires upgrading to any paid plan.
Which plan fits auditing 5,000 domains a month?
The Starter plan comfortably handles that volume. Because each check uses 10 credits, 5,000 audits require 50,000 credits, using one quarter of Starter's 200,000 monthly credits. That works out to about $1.50 per 1,000 calls, whereas the Free plan provides 20 calls each month.
How fresh are the DNSSEC validation results?
Results are evaluated in real time on every call. The service queries live DNSKEY, DS, and signature records directly to inspect the active zone rather than serving data from a stale cache or pre-scanned list.

Ready to build with DNSSEC Checker? Start with 200 free credits — one key unlocks all 300+ APIs.

Explore the catalog

300+ APIs on the same key and the same response shape.

Browse all APIs