dns-integrity · severity medium
DNSSEC
Share of domains without validated DNSSEC — unsigned, or signed with no DS record at the parent.
Measured every Tuesday · last updated
How it is measured
local probe (deliberately, ADR-0009): DNSKEY at the child, then DS at the parent. Denominator: any.
Why it matters
broken_chain is the quiet failure and the reason this metric exists — DNSKEY published but no DS at the parent means the zone is signed and unverifiable. The operator has done the work, the dashboard says DNSSEC is on, and no resolver on earth validates it. Unsigned is merely the default.
Limits of this measurement
Must be measured locally. The DomainAPI health endpoint exposes no DNSSEC state and resolves DS at the child, which cannot distinguish broken_chain from signed.
The base rate
Two independent populations. The global, domain-anchored figure is unbiased; the company-anchored figures are built by matching company names to domains and skew toward more digitally-mature firms. Both are published, so the gap is visible.
By company size band
Company-anchored cuts (national registries with a size proxy), split by size band. Right-hand figure is the share not meeting the control.
Every segment
Pick one to see the citable answer for a company like yours, with its trend and methodology.
Show the remaining 61 segments
Slices below 100 measured members are withheld rather than shown with a wide interval — an absent country or issuer means too little data, not zero failures. Licensed CC BY 4.0. Machine-readable data per segment: append .json or .csv to its URL.