DNSEC documentation

Learn how DNSEC reports work and how to interpret each security check.

Welcome to the DNSEC documentation. These guides explain what each report section means and how to act on the findings.

What DNSEC checks

DNSEC runs passive DNS security reconnaissance on a domain. A lookup produces a structured report with sections such as:

  • Chain of trust — DNS delegation and signing posture from the root down to your nameservers
  • Infrastructure — Nameserver, mail, and web hosting signals exposed in DNS
  • Similar domains — Lookalike domains that could be used for phishing or brand abuse
  • Resolver consistency — Whether public resolvers agree on answers for your zone
  • Risk assessment — Prioritized issues drawn from the checks above
  • Remediation — Recommended fixes for the highest-impact findings

Getting started

If you are new to DNSEC, start with Getting started, then browse the report checks for detail on each section.

On this page