Búsqueda Registro DS
Ver registros de Firmante de Delegación para validación DNSSEC.
Cómo Usar Esta Herramienta
- Qué Ingresar
- Enter a domain to check its DS (Delegation Signer) records at the parent zone.
- Qué Obtienes
- Shows DS records with key tag, algorithm, digest type, digest value, and whether they match the corresponding DNSKEY records.
Cómo Interpretar los Resultados
DS records at the parent zone should match the DNSKEY records in the child zone. Algorithm 13 (ECDSAP256SHA256) or 8 (RSASHA256) are recommended. Digest type 2 (SHA-256) is preferred over type 1 (SHA-1). Missing DS records mean the DNSSEC chain is broken even if the zone is signed.
Problemas Comunes y Soluciones
Stale DS records after key rollover break the chain of trust. Algorithm mismatch between DS and DNSKEY causes validation failures. Some registrars do not support all DNSSEC algorithms.

