dotvitals

DNSSEC could not be checked

InfoConfirmeddns.dnssec.probe-unavailable

What this check looks for

We could not read your zone's signing records, so none of the DNSSEC checks ran. This says nothing about whether your domain is signed — only that we could not look.

Why it matters

An empty DNSSEC panel and a clean one must never look the same. This finding is what keeps them distinguishable.

What it costs your score

This check never deducts. It reports a fact — or reports that something could not be verified — and is shown on the report without moving the score.

Severity
info
Default confidence
confirmed
Status when triggered
info
Deduction
0 points
Family cap
none
Category
DNSSEC
Module
Dns dnssec
Fix owned by
user
In the ruleset since
2026.09

How the whole score is calculated

Technical detail

The DNSSEC checks were not run: ‹reason›. Reading DNSKEY and denial-of-existence records requires queries with the DO bit set sent directly to the zone's own nameservers, which is only possible from the probe host. Nothing here is assumed to pass in its absence.

Standards and references

Test this on your domain

Run the check that produces this finding, on its own, against any domain.

Open the dns dnssec checker

Other dns dnssec checks