Dns Trace
dns_traceTrace DNS delegation from root to authoritative nameservers, revealing zone cuts and DNSSEC signing status. Detects broken chain of trust when a signed zone lacks a parent DS record.
Instructions
Trace DNS resolution from root to authoritative nameservers.
Walks the actual delegation chain (zone cuts) from the root down, showing each zone's nameservers and DNSSEC signing status. Labels that are not their own zone (e.g. 'www' as a record inside a parent zone) are skipped so they are not mistaken for a broken delegation.
This traces the delegation/chain-of-trust structure, which is independent of any particular record type.
A DNSSEC break is reported when a zone is signed (publishes DNSKEY) but its parent publishes no DS record for it — an "island of security" that breaks the chain of trust.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Domain name to trace (e.g. 'example.com') |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| query_name | Yes | Name that was traced | |
| break_point | No | Zone where DNSSEC chain breaks, if applicable | |
| delegation_chain | Yes | Zone cuts from the root down to the queried name | |
| dnssec_chain_intact | Yes | False if a signed zone has no DS in its parent (chain of trust broken) |