DNS resolver registry · measured 2026-09-24

Public DNS resolvers that validate DNSSEC

DNSSEC lets a resolver prove that an answer was signed by the zone's owner. A validating resolver refuses answers whose signatures fail. We asked each resolver for three domains that are deliberately mis-signed. 11 of 20 operators refused all three; 9 returned addresses for all three.

Questions

Common questions

How can I test whether my DNS resolver validates DNSSEC?

Look up a deliberately mis-signed name such as dnssec-failed.org. A validating resolver returns SERVFAIL; a non-validating one returns an address. Check a second broken domain as well, because one test name can change.

Which free DNS resolvers validate DNSSEC?

In our 2026-09-24 test: Cloudflare 1.1.1.1, Google Public DNS, Quad9, OpenDNS, AdGuard DNS, CleanBrowsing, Control D Free DNS, Mullvad DNS, DNS.SB, DNS4EU, DNS.WATCH.