d4 · tools · dnssec & caa
Enter a domain and this server reads its zone-security records straight from DNS: whether certificate issuance is fenced with CAA, whether DNSSEC signing records are published, plus its NS, SOA and MX. This complements the browser-side DNS lookup & latency tool, which races public resolvers from your own machine.
CAA, NS, SOA and MX are read through the server's own resolver. DNSSEC is checked separately against a public validating resolver (Cloudflare), and the verdict reflects whether that resolver authenticated the answer (the AD flag), not merely whether signing records exist. Lookups are rate limited and never logged.