DNSSEC Check Record: Lucy.ns.cloudflare.com

Let's check if the DNSSEC extension is enabled for the domain Lucy.ns.cloudflare.com by reviewing all zones, record types, counts, and propagation times. The test is fast, reliable, and concise.

If you are the domain owner of Lucy.ns.cloudflare.com and haven't enabled DNSSEC yet, now is the perfect time to do so and protect your domain from hijacking, spoofing, hackers and create an extra layer of cyber security.




Website Server Overview
Website: Lucy.ns.cloudflare.com
Server IP: 173.245.58.133
Resolved Hostname: lucy.ns.cloudflare.com
Domain Extension:com

Website Server Location
DNSSEC

-------------------------------------------

Zone: (Root zone) - 0.02 seconds
Record TypeCountDetails
DNSKEY ❌0None
DS ✔️1Okk+rDSN+FI01hJCbCQzc4RPYn+UL3mKag== )
RRSIG ✔️3. 86023 IN NSEC aaa. NS SOA RRSIG NSEC DNSKEY TYPE63
. 86023 IN RRSIG SOA 8 0 86400 20250627170000 (
. 86023 IN RRSIG NSEC 8 0 86400 20250627170000 (
NSEC ✔️2. 86023 IN NSEC aaa. NS SOA RRSIG NSEC DNSKEY TYPE63
. 86023 IN RRSIG NSEC 8 0 86400 20250627170000 (
NSEC3 ❌0None
Delegation is secure with DS records.
RRSIG Analysis:
Latest Expiration: 2025-06-27 17:00:00
DNSSEC is active for this zone.

-------------------------------------------

Zone: com (TLD) - 0.01 seconds
Record TypeCountDetails
DNSKEY ❌0None
DS ❌0None
RRSIG ✔️3CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 746 IN NSEC3 1 1 0 - CK0Q3UDG8CEKKAE7RUKPGCT1DVSSH8LL NS SOA RRSIG DNSKEY NSEC3PARAM
com. 746 IN RRSIG SOA 13 1 900 20250622053923 (
CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 746 IN RRSIG NSEC3 13 2 900 20250620002602 (
NSEC ❌0None
NSEC3 ✔️2CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 746 IN NSEC3 1 1 0 - CK0Q3UDG8CEKKAE7RUKPGCT1DVSSH8LL NS SOA RRSIG DNSKEY NSEC3PARAM
CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 746 IN RRSIG NSEC3 13 2 900 20250620002602 (
No delegation security found.
RRSIG Analysis:
Latest Expiration: 2025-06-22 05:39:23
DNSSEC is active for this zone.

-------------------------------------------

Zone: Lucy.ns.cloudflare.com (Domain) - 0.01 seconds
Record TypeCountDetails
DNSKEY ❌0None
DS ❌0None
RRSIG ✔️1Lucy.ns.cloudflare.com. 47912 IN RRSIG A 13 4 86353 20250615200130 (
NSEC ❌0None
NSEC3 ❌0None
No delegation security found.
RRSIG Analysis:
Latest Expiration: 2025-06-15 20:01:30
DNSSEC is active for this zone.
-------------------------------------------
Propagation Time for Each Zone (in seconds):
  • (Root zone) - 0.02 seconds
  • com: 0.01 seconds
  • Lucy.ns.cloudflare.com: 0.01 seconds
Global Conclusion: DNSSEC is enabled at the domain level.
DNSSEC Elements Legend:
  1. DNSKEY (DNS Key Record)
    • Contains the public key used to verify the signed DNS records.
    • Forms the foundation for verifying the authenticity of data in the DNSSEC system.
  2. DS (Delegation Signer Record)
    • Links subdomains to the parent domain.
    • Used to transfer the cryptographic chain of trust between the parent and child DNS zones.
  3. RRSIG (Resource Record Signature)
    • A digital signature for a specific DNS record.
    • Ensures the record has not been altered during transit and allows authenticity verification.
  4. NSEC (Next Secure Record)
    • Verifies that a specific record does not exist in the DNS zone.
    • Lists the next records in the zone file, ensuring integrity verification.
  5. NSEC3 (Next Secure Record, Version 3)
    • An improved version of NSEC that uses hash values to hide record names.
    • Offers improved privacy while enabling verification of missing records.