DNSSEC Validator
Trust, but verify. Then verify the verification.

What DNSSEC does
Normal DNS answers come with no proof they have not been tampered with — anyone on the path can forge a reply and your resolver will believe it. DNSSEC fixes that with signatures: the domain publishes DNSKEY records, signs its answers, and the parent zone publishes a DS record that anchors the whole chain up to the root. A validating resolver can then prove each answer is genuine. The two halves both matter. Keys without a DS record are like a notary stamp nobody registered — technically present, trusted by no one. And enabling it wrongly (expired signatures, broken key rollovers) can make a domain vanish for validating resolvers while looking fine to everyone else, which is why adoption has been cautious. This tool checks the public half of the setup: is a DS published at the parent, and are DNSKEYs published on the domain. If you are turning DNSSEC on, publish the keys first, then add the DS at your registrar, then verify here — in that order.