Report checks
Chain of trust
How DNSEC evaluates DNS delegation from the root to your nameservers.
The Chain of trust section maps the delegation path for your domain—from the DNS root through the TLD registry to your authoritative nameservers.
What we look for
- Valid delegation at each hop (NS records and glue where required)
- Consistent NS sets between parent and child zones
- DNSSEC-related signals where published (DS records, DNSKEY presence)
- Unexpected or dangling delegations that could enable takeover
Why it matters
A broken or inconsistent delegation chain can cause resolution failures, mail delivery issues, or opportunities for an attacker to insert themselves between visitors and your infrastructure.
Related checks
- Infrastructure — what your nameservers and records expose
- Resolver consistency — whether resolvers agree on your delegation