dotvitals

Signatures were read but not cryptographically verified

InfoConfirmeddns.dnssec.chain-unverified

What this check looks for

We checked that your DNSSEC records exist, that the link to your registry matches, and that no signature has expired. We did not verify the signatures themselves, and we are telling you rather than implying we did.

Why it matters

A DNSSEC report that says "valid" without saying what it validated is worth nothing. Knowing exactly which checks ran is what lets you decide whether you also need a full validator before, say, rolling a key.

What it costs your score

This check never deducts. It reports a fact — or reports that something could not be verified — and is shown on the report without moving the score.

Severity
info
Default confidence
confirmed
Status when triggered
info
Deduction
0 points
Family cap
none
Category
DNSSEC
Module
Dns dnssec
Fix owned by
user
In the ruleset since
2026.09

How the whole score is calculated

Technical detail

Verified in this scan: the DS records at your registry were recomputed from your published DNSKEY set and compared byte for byte; every RRSIG validity window was checked against the current time; algorithms and key sizes were read from the DNSKEY records; and public validating resolvers were asked whether they can resolve the domain. **Not** verified: no RRSIG signature was checked against its key, the chain from the root zone down was not walked, and NSEC/NSEC3 denial proofs were read but not validated. For a full validation, delv +vtrace ‹domain› or the Verisign DNSSEC debugger will do the cryptography.

Standards and references

Test this on your domain

Run the check that produces this finding, on its own, against any domain.

Open the dns dnssec checker

Other dns dnssec checks