Signatures were read but not cryptographically verified
What this check looks for
We checked that your DNSSEC records exist, that the link to your registry matches, and that no signature has expired. We did not verify the signatures themselves, and we are telling you rather than implying we did.
Why it matters
A DNSSEC report that says "valid" without saying what it validated is worth nothing. Knowing exactly which checks ran is what lets you decide whether you also need a full validator before, say, rolling a key.
What it costs your score
This check never deducts. It reports a fact — or reports that something could not be verified — and is shown on the report without moving the score.
- Severity
- info
- Default confidence
- confirmed
- Status when triggered
- info
- Deduction
- 0 points
- Family cap
- none
- Category
- DNSSEC
- Module
- Dns dnssec
- Fix owned by
- user
- In the ruleset since
- 2026.09
Technical detail
Verified in this scan: the DS records at your registry were recomputed from your published DNSKEY set and compared byte for byte; every RRSIG validity window was checked against the current time; algorithms and key sizes were read from the DNSKEY records; and public validating resolvers were asked whether they can resolve the domain. **Not** verified: no RRSIG signature was checked against its key, the chain from the root zone down was not walked, and NSEC/NSEC3 denial proofs were read but not validated. For a full validation, delv +vtrace ‹domain› or the Verisign DNSSEC debugger will do the cryptography.
Standards and references
Test this on your domain
Run the check that produces this finding, on its own, against any domain.
Other dns dnssec checks
- The zone is signed with a deprecated algorithm
- Validating resolvers refuse to resolve the domain
- The registry's DS record does not match any key in the zone
- The zone is signed but the registry has no DS record
- A DNSSEC key is shorter than the recommended size
- The zone's record names can be enumerated
- NSEC3 is configured with extra hash iterations
- NSEC3 opt-out weakens proof for unsigned subdomains
- DNSSEC could not be checked
- A DNSSEC signature has expired
- A DNSSEC signature expires within seven days
- The zone publishes keys but no signatures