---
id: "dnssec-validation"
kind: "glossary-term"
title: "DNSSEC validation"
language: "en"
category: "DNS and technical foundations"
updated: "2026-10-04T14:01:23Z"
canonical: "https://tldlog.com/glossary/dnssec-validation/"
translations:
  es: "https://tldlog.com/es/glosario/validacion-dnssec/"
  de: "https://tldlog.com/de/glossar/dnssec-validierung/"
  fr: "https://tldlog.com/fr/glossaire/validation-dnssec/"
  it: "https://tldlog.com/it/glossario/validazione-dnssec/"
  pt-BR: "https://tldlog.com/pt/glossario/validacao-dnssec/"
  ru: "https://tldlog.com/ru/glossariy/validatsiya-dnssec/"
  zh-Hans: "https://tldlog.com/zh/cihui/dnssec-yanzheng/"
---

# DNSSEC validation

The check a resolver makes to confirm that a DNS answer carries a correct DNSSEC signature linking back to a key it already trusts. If the check fails, the resolver returns an error instead of the answer. A domain with broken DNSSEC settings therefore disappears for users of such resolvers.

## related terms

- [DNSSEC](https://tldlog.com/glossary/dnssec/)
- [chain of trust](https://tldlog.com/glossary/chain-of-trust/)
- [trust anchor](https://tldlog.com/glossary/trust-anchor/)
- [SERVFAIL](https://tldlog.com/glossary/servfail/)
- [resolver](https://tldlog.com/glossary/resolver/)
