Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNSSEC Resolver Test site

    Scheduled Pinned Locked Moved DHCP and DNS
    2 Posts 2 Posters 56 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JonathanLeeJ
      JonathanLee
      last edited by

      i was wonder if anyone has checked out this site?

      https://wander.science/projects/dns/dnssec-resolver-test/

      Screenshot 2025-07-15 at 18.36.24.png

      Make sure to upvote

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @JonathanLee
        last edited by Gertjan

        @JonathanLee said in DNSSEC Resolver Test site:

        https://wander.science/projects/dns/dnssec-resolver-test/

        The patato checker.

        Uncheck :
        77b420f9-5499-4301-8050-7c1f6a6560d3-image.png

        and do the test again.

        So that page, and this one : http://www.dnssec-or-not.com/ test if you've checked the resolver's DNSSEC capability, or not ^^

        That web site is part of my collection of web sites that test several DNS(SEC) related things.
        I 'admin' several web servers ( = domain names), I also use site use this one https://dnsviz.net/d/test-domaine.fr/dnssec/ to check out a domain name DNSSEC capabilities, as I need to be sure it works = me not messing up things when deploying it.
        test-domaine.fr is a domain I rent and use to test things before I apply them on the domains that can't afford down time when I mess up (again).
        Remember : if you set up DNSSEC wrong on your web server, mail server ( actually DNS domain name server ), your domain name will 'vanish' from the Internet.
        DNSSEC was considered rocket science not so long ago and maybe it still is, as using it really implies that you know what DNS is.

        The good thing about pfSense : when you install it, and don't change (add, remove) any pfSense DNS settings, it will use DNSSEC out of the box without the user (admin) even being aware of anything.
        DNSSEC = that's why resolving (yourself, locally) is such a good thing.
        Forwarding means : you have to trust some one else.

        Last time I checked, half of Europe's web site are using DNSSEC, and the US was ... not really using it.
        That changed a lot the last several years : DNSSEC is now somewhat mandatory for all government hosted sites world wide.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 1
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.