{"uid":"cap_EydbxZXclq6JemJlVRc-O","slug":"dnssec-check-51449c73","name":"DNSSEC Check","description":"DNSSEC check for a domain: whether DS and DNSKEY records exist, whether the resolver validates the chain (AD flag), signing algorithms used. Security posture and DNS hygiene audits. $0.01 per check.","url":"https://intel.rallylive.ca/dns/dnssec","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_WcIdqz_HK30JoP6piCLGP","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks a domain's DNSSEC status including DS and DNSKEY record presence, resolver validation (AD flag), and signing algorithms used.","exampleAgentPrompt":"Can you check whether example.com has DNSSEC properly set up — I want to know if the DS and DNSKEY records are present, whether the resolver is validating the chain, and what signing algorithms are being used?","exampleUseCases":[{"title":"Pre-acquisition DNS security audit","prompt":"We're considering acquiring a company at domain acmecorp.io — can you check their DNSSEC status and tell me if their DS and DNSKEY records are in place and whether the chain of trust validates correctly?"},{"title":"Security compliance check for client domain","prompt":"I need to verify DNSSEC compliance for our client's domain clientbrand.com — check if DNSSEC is enabled, whether the resolver is setting the AD flag, and what signing algorithms they're using."},{"title":"Monitoring DNS hygiene after migration","prompt":"We just migrated our DNS to a new registrar for ourcompany.net — can you run a DNSSEC check to confirm the DS and DNSKEY records are still valid and the chain of trust hasn't broken?"}],"resultDescription":"Returns whether DS and DNSKEY records exist for the domain, whether the resolver validates the DNSSEC chain (indicated by the AD flag), the signing algorithms in use, and an overall assessment of the domain's DNSSEC security posture.","failureModes":["Domain does not exist or is unreachable — returns no records found","Domain has no DNSSEC records (unsigned zone) — returns absent DS/DNSKEY status","Resolver cannot validate chain (broken DNSSEC) — AD flag returns false with error details","Invalid or malformed domain name input — returns validation error","Network timeout reaching authoritative nameservers — returns timeout error"],"whenToPreferThis":"Choose this endpoint when you need a focused, fast DNSSEC-specific security check for a single domain — covering DS records, DNSKEY records, resolver AD flag validation, and signing algorithms — rather than a broad DNS or domain intelligence report. Ideal for security audits, compliance checks, pre-acquisition due diligence, or post-migration validation where DNSSEC chain integrity is the primary concern.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T13:13:20.836Z","isFirstParty":false}