Overview
DNSSEC Checker works by querying DNSKEY, DS, and RRSIG records for a domain and validating the cryptographic chain of trust. It identifies whether DNSSEC is properly configured, highlights any validation errors, and derives a deployment-health risk score that distinguishes an unhardened domain from one with a broken chain of trust.
Live Test DNSSEC Check Skill Skill →
The tool
Once your client is connected to the VerveKit server, this appears in its tool list as DNSSECCheckSkill. It is read-only and open-world — it fetches and never mutates anything on your side — so most clients call it without asking you to confirm.
{
"name": "DNSSECCheckSkill",
"arguments": {
"domain": "cloudflare.com"
}
}You do not name the tool yourself; the model picks it. Asking about cloudflare.com in the terms this skill covers is enough for it to reach for DNSSECCheckSkill on its own — naming it explicitly also works, and is the way to force the call.
Connecting
One server URL covers every skill in the catalog, including this one. Authorization is OAuth: the client opens a browser once, and there is no key to paste into a config file.
{
"mcpServers": {
"vervekit": {
"url": "https://api.vervekit.com/v1/mcp"
}
}
}https://api.vervekit.com/v1/mcpPer-client setup — Claude, Cursor, VS Code, ChatGPT — is on the MCP setup page.
Arguments
These are the properties on the tool's inputSchema, so a well-behaved client validates them before the call is made. Premium arguments are accepted on every plan but only take effect on plans that include them.
| Argument | Type | Description |
|---|---|---|
domainRequired | string | The domain name to check DNSSEC configuration for domain |
What the model gets back
The result carries a structuredContent object matching the tool's declared outputSchema, so a client reads fields without parsing prose. status is "ok" and error is null on success; a null field means the value was not available for that input, not that the call failed.
{
"status": "ok",
"error": null,
"data": {
"domain": "cloudflare.com",
"dnssecEnabled": true,
"valid": true,
"records": {
"dnskey": 3,
"ds": 2,
"nsec": "NSEC3"
},
"errors": [],
"details": {
"dnskeyCount": 3,
"dsCount": 2
},
"status": "DNSSEC is properly configured with DS records at parent",
"recommendation": "DNSSEC is properly configured",
"riskScore": 5,
"riskLevel": "low"
}
}
Response fields
Paths are relative to data. Premium fields are absent rather than zeroed on plans that do not include them, so check for presence instead of comparing to 0.
| Field | Type | Example | Description |
|---|---|---|---|
domain | string | cloudflare.com | Domain that was checked |
dnssecEnabled | boolean | true | Whether DNSSEC is enabled |
valid | boolean | true | Whether DNSSEC configuration is valid |
recordsPremium | object | {…} | DNSKEY and DS record details |
records.dnskeyPremium | number | 3 | Number of DNSKEY records published by the zone |
records.dsPremium | number | 2 | Number of DS records held by the parent zone |
records.nsecPremium | string | NSEC3 | Number of NSEC or NSEC3 records used to prove non-existence; null when none were returned |
errors | array | [] | Problems found in the chain of trust; empty when DNSSEC validates |
details | object | {…} | Record counts behind the verdict |
details.dnskeyCount | number | 3 | Number of DNSKEY records seen |
details.dsCount | number | 2 | Number of DS records seen at the parent |
status | string | DNSSEC is properly configured with DS records at parent | Plain-language verdict on the domain's DNSSEC configuration |
recommendation | string | DNSSEC is properly configured | What to do about the current configuration |
riskScorePremium | number | 5 | Composite 0-100 DNSSEC deployment-health score. A fully valid chain of trust scores low; a domain that published keys but never lodged its DS record at the parent zone (a broken chain that can break resolution) scores high; an undeployed domain scores in between |
riskLevelPremium | string | low | Risk band derived from the score: low, medium or high |
Failure modes
Errors come back as tool errors carrying a sentence the model can act on, not a bare status code. Error handling covers the full list.
| Status | What it means |
|---|---|
400 / 422 | The arguments did not validate. The message names the offending one. |
401 | The OAuth session is invalid or expired — reconnect the server. |
403 | Blocked by a key restriction or an IP allow-list. Never a bad identity. |
404 | This skill is not part of VerveKit. Check the catalog. |
429 | Out of credits, or a brief rate limit. The message tells them apart. |
A call costs 10 credits each time the tool actually runs; a model that reasons about the tool without calling it costs nothing.
Use cases
- Security Auditing
- Verify that domains have properly configured DNSSEC to prevent DNS spoofing and cache poisoning attacks
- Compliance Checking
- Ensure domains meet security compliance requirements that mandate DNSSEC
- Domain Monitoring
- Monitor DNSSEC status and get alerts if configuration becomes invalid
- Troubleshooting
- Diagnose DNSSEC validation failures and identify misconfigured records
Other ways to use DNSSEC Check Skill
Set up DNSSEC Check Skill on VerveKit, or reach the same source a different way. Your VerveKit account and credits work on all of them — one key, one balance.
Related
More in Domain Data: