Authoritative servers
NS records should point to the expected authoritative servers and answer consistently.
Tool
Checks NS, SOA, basic domain delegation consistency and DNSSEC records such as DS, DNSKEY and RRSIG.
DNS audit
The DataHouse DNS delegation checker reviews nameservers, SOA data and DNSSEC records such as DS, DNSKEY and RRSIG. It is useful after DNS operator changes, registrar changes and DNSSEC deployment.
NS records should point to the expected authoritative servers and answer consistently.
SOA data helps identify the primary server, serial and zone responsibility.
DS, DNSKEY and RRSIG show whether a validating resolver can build a chain of trust.
DNS delegation is the foundation for websites, mail, certificates and DNSSEC. Small inconsistencies can look like application outages.
Start with NS and SOA consistency, then check DNSSEC records and the services that depend on the domain.