DNSKEY presence

DNSKEY presence shows whether DNSKEY records are publicly visible for the relevant zone where .auDO checks them.

Observed evidenceDNSSECDNS-side source

What .auDO observes

Direct DNSKEY visibility

.auDO records whether DNSKEY material is visible at collection time. This is supporting direct evidence used within the combined DNSSEC posture view.

Technical fields

dnskey_presentdns_raw.dnskey_presentdnssec_mismatch

Why it is observed

DNSKEY is one visible part of DNSSEC posture

Why it matters

DNSKEY visibility can indicate published DNSSEC key material and supports comparison with registration-side DNSSEC assertions.

What visible change may mean

A change may reflect rollout, key rotation, provider migration, delegation movement, collection timing or maintenance.

Interpretation limits

DNSKEY presence is not the complete chain

DNSKEY visibility alone does not establish a valid DS relationship, successful resolver validation or complete operational quality.

Common retained observations

DNSKEY and assertion-gap movement

DNSKEY presence changeDNSSEC assertion gap change

Where to use this evidence

Read DNSKEY within combined posture

Related concept

How DNSSEC works

Related signals