Defaults.Exposed

Defaults.ExposedSeptember 2026 censusv10 registry › DNSSEC (DS)

DNSSEC (DS)

Methodology v10 · canonical ID dnssec-ds · DNS Security · scored · census as of September 5, 2026

Stops attackers hijacking your domain to send visitors to a fake copy of your site.

Definition

Canonical IDdnssec-ds
CategoryDNS Security
Grade impactScored, counts toward the grade
PassA DS record exists at the parent zone, anchoring the DNSSEC chain of trust.
FailNo DS record exists (the zone is unsigned from the parent’s view), or the chain is broken.
Example (passing)example.com. IN DS 12345 13 2 A1B2C3…

No-data rule: when this check couldn't be determined for a domain (timeout, SERVFAIL, redacted source) it returns N/A and is excluded from that domain's scoring denominator: "couldn't determine" is never counted as a failure. "Determined absent" is a real fail.

Prevalence across the census

6.86% of graded domains have a valid, fully validating DNSSEC chain (21,732,692 of 316,600,902, as of September 5, 2026).

The census reports DNSSEC as a single signed-and-validating measure: not split into DS vs DNSKEY. A further share are signed but broken.

Census denominator: 316,600,902 graded domains. Aggregates only: never an individual domain's result.

Fix it

Plain-English impact, cost of ignoring it, and step-by-step remediation: defaults.exposed/fix/dnssec

Cite this check

Defaults.Exposed, "DNSSEC (DS) (dnssec-ds)", Grading Methodology v10 (census as of September 5, 2026). https://defaults.exposed/methodology/dnssec-ds

Permalink: https://defaults.exposed/methodology/dnssec-ds · All 34 checks: v10 registry · Machine-readable: /methodology/checks.json · Licence: open data