DNSSEC could not be checked
What this check looks for
We could not read your zone's signing records, so none of the DNSSEC checks ran. This says nothing about whether your domain is signed — only that we could not look.
Why it matters
An empty DNSSEC panel and a clean one must never look the same. This finding is what keeps them distinguishable.
What it costs your score
This check never deducts. It reports a fact — or reports that something could not be verified — and is shown on the report without moving the score.
- Severity
- info
- Default confidence
- confirmed
- Status when triggered
- info
- Deduction
- 0 points
- Family cap
- none
- Category
- DNSSEC
- Module
- Dns dnssec
- Fix owned by
- user
- In the ruleset since
- 2026.09
Technical detail
The DNSSEC checks were not run: ‹reason›. Reading DNSKEY and denial-of-existence records requires queries with the DO bit set sent directly to the zone's own nameservers, which is only possible from the probe host. Nothing here is assumed to pass in its absence.
Standards and references
Test this on your domain
Run the check that produces this finding, on its own, against any domain.
Other dns dnssec checks
- The zone is signed with a deprecated algorithm
- Validating resolvers refuse to resolve the domain
- Signatures were read but not cryptographically verified
- The registry's DS record does not match any key in the zone
- The zone is signed but the registry has no DS record
- A DNSSEC key is shorter than the recommended size
- The zone's record names can be enumerated
- NSEC3 is configured with extra hash iterations
- NSEC3 opt-out weakens proof for unsigned subdomains
- A DNSSEC signature has expired
- A DNSSEC signature expires within seven days
- The zone publishes keys but no signatures