↑ ↓ select, Enter open, Esc close

Check whether DNSSEC works for a domain

Adjust the values, the command updates live
user@server
dig @1.1.1.1 +dnssec example.com SOA | grep -E "flags:|RRSIG|status:"

Sends the query to a validating resolver and filters out status, flags and signatures. If ad appears in the flags and an RRSIG is shown, the zone is signed and valid. A SERVFAIL status on an otherwise working domain points to broken DNSSEC, for example an outdated DS record at the registrar after a nameserver change.

Also searched as

  • check if dnssec is enabled
  • domain unreachable after enabling dnssec
  • servfail because of dnssec

Related one-liners

All in DNS

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.