ToolsCVE trackerATT&CKCIDRDNSEmail securityHeadersTrackersTLSMy connectionCSP builderEmail headersJWTCert decoderPassphrasePassword checkHash & encodesecurity.txtDNSSEC & CAA

d4 · tools · dnssec & caa

DNSSEC & CAA check

Enter a domain and this server reads its zone-security records straight from DNS: whether certificate issuance is fenced with CAA, whether DNSSEC signing records are published, plus its NS, SOA and MX. This complements the browser-side DNS lookup & latency tool, which races public resolvers from your own machine.

CAA, NS, SOA and MX are read through the server's own resolver. DNSSEC is checked separately against a public validating resolver (Cloudflare), and the verdict reflects whether that resolver authenticated the answer (the AD flag), not merely whether signing records exist. Lookups are rate limited and never logged.