DNSSEC Check Record: Nero.ns.cloudflare.com

Let's check if the DNSSEC extension is enabled for the domain Nero.ns.cloudflare.com by reviewing all zones, record types, counts, and propagation times. The test is fast, reliable, and concise.

If you are the domain owner of Nero.ns.cloudflare.com and haven't enabled DNSSEC yet, now is the perfect time to do so and protect your domain from hijacking, spoofing, hackers and create an extra layer of cyber security.




Website Server Overview
Website: Nero.ns.cloudflare.com
Server IP: 162.159.44.28
Resolved Hostname: nero.ns.cloudflare.com
Domain Extension:com

Website Server Location
DNSSEC

-------------------------------------------

Zone: (Root zone) - 0.01 seconds
Record TypeCountDetails
DNSKEY ❌0None
DS ✔️1Okk+rDSN+FI01hJCbCQzc4RPYn+UL3mKag== )
RRSIG ✔️3. 84504 IN NSEC aaa. NS SOA RRSIG NSEC DNSKEY TYPE63
. 84504 IN RRSIG SOA 8 0 86400 20250627170000 (
. 84504 IN RRSIG NSEC 8 0 86400 20250627170000 (
NSEC ✔️2. 84504 IN NSEC aaa. NS SOA RRSIG NSEC DNSKEY TYPE63
. 84504 IN RRSIG NSEC 8 0 86400 20250627170000 (
NSEC3 ❌0None
Delegation is secure with DS records.
RRSIG Analysis:
Latest Expiration: 2025-06-27 17:00:00
DNSSEC is active for this zone.

-------------------------------------------

Zone: com (TLD) - 0.01 seconds
Record TypeCountDetails
DNSKEY ❌0None
DS ❌0None
RRSIG ✔️3CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 148 IN NSEC3 1 1 0 - CK0Q3UDG8CEKKAE7RUKPGCT1DVSSH8LL NS SOA RRSIG DNSKEY NSEC3PARAM
com. 148 IN RRSIG SOA 13 1 900 20250622055438 (
CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 148 IN RRSIG NSEC3 13 2 900 20250620002602 (
NSEC ❌0None
NSEC3 ✔️2CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 148 IN NSEC3 1 1 0 - CK0Q3UDG8CEKKAE7RUKPGCT1DVSSH8LL NS SOA RRSIG DNSKEY NSEC3PARAM
CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 148 IN RRSIG NSEC3 13 2 900 20250620002602 (
No delegation security found.
RRSIG Analysis:
Latest Expiration: 2025-06-22 05:54:38
DNSSEC is active for this zone.

-------------------------------------------

Zone: Nero.ns.cloudflare.com (Domain) - 0.01 seconds
Record TypeCountDetails
DNSKEY ❌0None
DS ❌0None
RRSIG ✔️1Nero.ns.cloudflare.com. 46564 IN RRSIG A 13 4 86353 20250615200422 (
NSEC ❌0None
NSEC3 ❌0None
No delegation security found.
RRSIG Analysis:
Latest Expiration: 2025-06-15 20:04:22
DNSSEC is active for this zone.
-------------------------------------------
Propagation Time for Each Zone (in seconds):
  • (Root zone) - 0.01 seconds
  • com: 0.01 seconds
  • Nero.ns.cloudflare.com: 0.01 seconds
Global Conclusion: DNSSEC is enabled at the domain level.
DNSSEC Elements Legend:
  1. DNSKEY (DNS Key Record)
    • Contains the public key used to verify the signed DNS records.
    • Forms the foundation for verifying the authenticity of data in the DNSSEC system.
  2. DS (Delegation Signer Record)
    • Links subdomains to the parent domain.
    • Used to transfer the cryptographic chain of trust between the parent and child DNS zones.
  3. RRSIG (Resource Record Signature)
    • A digital signature for a specific DNS record.
    • Ensures the record has not been altered during transit and allows authenticity verification.
  4. NSEC (Next Secure Record)
    • Verifies that a specific record does not exist in the DNS zone.
    • Lists the next records in the zone file, ensuring integrity verification.
  5. NSEC3 (Next Secure Record, Version 3)
    • An improved version of NSEC that uses hash values to hide record names.
    • Offers improved privacy while enabling verification of missing records.