DNSSEC Validator: How to Check Your Domain's Chain of Trust (2026)
Table of Contents
DNSSEC คืออะไร
DNSSEC (Domain Name System Security Extensions) คือชุดมาตรฐานที่เพิ่มการตรวจสอบความถูกต้องด้วยลายเซ็นดิจิทัลให้กับ DNS ช่วยป้องกันการโจมตีแบบ DNS Cache Poisoning ที่แฮกเกอร์อาจสร้าง DNS Record ปลอมเพื่อเปลี่ยนเส้นทาง Traffic ของผู้ใช้ไปยังเซิร์ฟเวอร์อันตราย
DNSSEC (Domain Name System Security Extensions) is a suite of Internet Engineering Task Force (IETF) specifications that adds cryptographic authentication to DNS responses. Without DNSSEC, an attacker who can poison a resolver's cache can redirect users to malicious servers even when they type the correct domain name.
- ป้องกัน DNS Spoofing และ Cache Poisoning
- ยืนยันว่า DNS Record มาจากเจ้าของโดเมนจริง
- สร้าง Chain of Trust จาก Root DNS ลงมาถึงโดเมน
- รองรับทุก Record Type: A, AAAA, MX, TXT, NS
- บังคับใช้ใน Critical Infrastructure: Banking, Government, Healthcare
ทำไม DNSSEC ถึงสำคัญ
ปัญหา DNS Spoofing ไม่ใช่เรื่องเล็กน้อย งานวิจัยของ NIST พบว่า DNS Cache Poisoning Attack ยังเกิดขึ้นในปัจจุบัน โดยเฉพาะบน Resolver ที่ไม่ได้รับการอัปเดต โดเมนที่ไม่มี DNSSEC สามารถถูกโจมตีได้แม้ใช้ HTTPS เพราะ TLS ป้องกัน Transport Layer แต่ไม่ป้องกัน DNS ที่ Resolve ชื่อโดเมนก่อน
DNS spoofing remains a real threat. A resolver cache poisoning attack can redirect users to phishing sites or malicious servers even when they use HTTPS — because TLS secures the transport layer but cannot verify that the DNS resolution step correctly identifies the server. DNSSEC closes this gap by making every DNS response verifiable.
- HTTPS ไม่สามารถป้องกัน DNS Spoofing ได้ด้วยตัวเอง
- Email Delivery ถูกโจมตีผ่าน MX Record ปลอมได้
- DNSSEC เป็นพื้นฐานของ DANE (TLS Authentication ผ่าน DNS)
- Google, Cloudflare, และ ICANN แนะนำให้ทุกโดเมนเปิด DNSSEC
- โดเมน .th ของไทย รองรับ DNSSEC ผ่าน THNIC แล้ว
Chain of Trust และ DS Record
DNSSEC ใช้ Chain of Trust ที่เชื่อมจาก Root Zone (Root DNS) ผ่าน TLD Name Server (เช่น .com, .th) ลงมาถึง Authoritative Name Server ของโดเมน ทุก Link ในห่วงโซ่นี้ต้องมีลายเซ็นที่ถูกต้อง
DNSSEC establishes a chain of trust from the DNS root zone down to individual domain zones. The root zone signs delegations to TLD name servers (.com, .th etc.), TLD name servers sign delegations to authoritative name servers for individual domains, and each zone signs its own resource records. Every link in this chain must be valid for DNSSEC validation to succeed.
- DS Record (Delegation Signer): เก็บอยู่ที่ TLD Name Server ชี้ไปยัง DNSKEY ของโดเมนลูก
- KSK (Key-Signing Key): Key หลักที่เซ็น DNSKEY Record และถูก Hash เก็บใน DS
- ZSK (Zone-Signing Key): Key รองที่เซ็น Zone Data ทุก Record
- ถ้า DS ไม่อยู่ที่ TLD = DNSSEC ไม่ถูก Validate (Unsigned)
- ถ้า DS ไม่ตรงกับ DNSKEY = Chain of Trust ขาด (Bogus)
example.com. 3600 IN DS 12345 8 2 abc123...sha256hash...ตัวเลข 12345 = Key Tag, 8 = Algorithm (RSA/SHA-256), 2 = Digest Type (SHA-256)
DNSKEY: KSK และ ZSK
DNSKEY Record เก็บ Public Key ที่ใช้ตรวจสอบลายเซ็น DNSSEC แต่ละโดเมนมี DNSKEY อย่างน้อย 2 ตัว: KSK ที่เซ็น DNSKEY Record ด้วยตัวเอง และ ZSK ที่เซ็น Record อื่นทั้งหมดในโซน
Each DNSSEC-enabled zone publishes at least two DNSKEY records. The Key-Signing Key (KSK) has the Zone Key flag set and is used exclusively to sign the DNSKEY RRset — its hash appears in the DS record held by the parent zone. The Zone-Signing Key (ZSK) signs all other records in the zone. This two-key design allows zone operators to rotate ZSKs frequently without updating the DS record at the registrar.
- KSK: Flags=257, ต้องตรงกับ DS Record ที่ TLD
- ZSK: Flags=256, หมุนเวียนบ่อยกว่า KSK ได้โดยไม่ต้องเปลี่ยน DS
- Algorithm ที่ใช้บ่อย: 8 (RSA/SHA-256), 13 (ECDSA P-256/SHA-256)
- Key Tag = ค่า 16-bit ที่คำนวณจาก Key ใช้จับคู่ DS↔DNSKEY
- NSEC3 ป้องกัน Zone Walking (ดู Section ถัดไป)
RRSIG: ลายเซ็นดิจิทัลของ DNS Record
RRSIG (Resource Record Signature) คือลายเซ็นดิจิทัลที่แนบมากับทุก Record Set ใน Zone ที่เปิด DNSSEC Validator ที่ Analyze.in.th ตรวจสอบ RRSIG บน SOA Record (ยืนยันว่า Zone มีลายเซ็น) และบน DNSKEY Record (ยืนยัน KSK สามารถเซ็น DNSKEY ได้)
Every resource record set in a DNSSEC-signed zone is accompanied by one or more RRSIG records containing the cryptographic signature over the record set. The Analyze.in.th DNSSEC Validator checks RRSIG records on the SOA (confirming the zone is signed) and on the DNSKEY RRset (confirming the KSK signs the DNSKEY set, completing the chain of trust).
- RRSIG บน SOA = Zone ถูก Sign แล้ว
- RRSIG บน DNSKEY = KSK สามารถยืนยันตัวเองได้
- Signature Expiration = วันหมดอายุ (ต้องต่ออายุก่อน Expire)
- ถ้า RRSIG Expire = DNSSEC Validation ล้มเหลว, โดเมน Resolve ไม่ได้
- Monitoring RRSIG Expiry สำคัญพอๆ กับ SSL Certificate
NSEC/NSEC3: Denial of Existence
DNSSEC ต้องสามารถ "ยืนยัน" ว่าไม่มี Record อยู่ได้ด้วย ไม่ใช่แค่ยืนยันว่ามี โดยใช้ NSEC หรือ NSEC3 Record เพื่อ Authenticate คำตอบ NXDOMAIN (Record ไม่มีอยู่)
DNSSEC must also authenticate negative responses — confirming that a record does not exist is just as important as confirming it does. NSEC records create a cryptographically signed linked list of all names in the zone. NSEC3 hashes the names first to prevent zone enumeration (zone walking), making it the preferred choice for privacy-conscious zone operators.
- NSEC: ยืนยัน NXDOMAIN แต่เปิดเผย Zone Records ทั้งหมด (Zone Walking)
- NSEC3: Hash ชื่อก่อนจึงป้องกัน Zone Walking ได้
- NSEC3 เป็น Default บน Hosting Provider ส่วนใหญ่
- เครื่องมือตรวจ: Analyze.in.th DNSSEC Validator แสดง NSEC/NSEC3 status
วิธีใช้ DNSSEC Validator ที่ Analyze.in.th
DNSSEC Validator ที่ Analyze.in.th ตรวจสอบ Chain of Trust ทั้งหมดโดยไม่ต้องติดตั้งซอฟต์แวร์ใด ทำงานผ่าน Browser ได้เลย
The Analyze.in.th DNSSEC Validator checks the complete DNSSEC chain of trust for any domain in seconds — no software installation required. It uses a DNSSEC-aware resolver built into the platform to query DS, DNSKEY, and RRSIG records and verify their cryptographic relationships.
- เปิด https://dnsxray.com/dnssec.php
- พิมพ์ชื่อโดเมนในช่อง เช่น
example.com - กด Validate DNSSEC
- อ่านผลลัพธ์: สีเขียว = ผ่าน, สีเหลือง = คำเตือน, สีแดง = ล้มเหลว
ผลลัพธ์ที่ได้รวมถึง: DS Record ที่ TLD, DNSKEY (KSK/ZSK พร้อม Key Tag), RRSIG บน SOA และ DNSKEY, การตรวจสอบ DS↔DNSKEY Match, และ NSEC/NSEC3 Status
The result covers: DS record at the TLD parent zone; DNSKEY records (KSK and ZSK with key tags); RRSIG signatures on SOA and DNSKEY; DS-to-DNSKEY key tag match verification; and NSEC/NSEC3 denial-of-existence support.
วิธีเปิด DNSSEC บนโดเมนของคุณ
การเปิด DNSSEC ต้องทำสองส่วน: เปิด DNSSEC ที่ Name Server ของโดเมน และส่ง DS Record ไปยัง Registrar เพื่อให้ TLD บันทึก
Enabling DNSSEC requires action at two levels. First, the authoritative name server must sign the zone and publish DNSKEY records. Second, the DS record (a hash of the KSK) must be submitted to the domain registrar, which publishes it in the parent TLD zone. Both steps must be completed for the chain of trust to form.
- DirectAdmin Hosting: ไปที่ DNS Management → เปิด DNSSEC → ระบบสร้าง Key อัตโนมัติ → Copy DS Record ไปวางที่ Registrar
- Cloudflare: เปิด DNSSEC ใน DNS Settings → Copy DS Record → วางที่ Registrar ของโดเมน
- cPanel/WHM: Zone Editor → DNSSEC Keys → Generate → Copy DS
- ตรวจสอบหลังเปิด: ใช้ Analyze.in.th DNSSEC Validator ทดสอบว่า Chain of Trust สมบูรณ์
- ระวัง: ถ้าตั้งค่าผิด โดเมน Resolve ไม่ได้ ตรวจก่อน Enable บน Production
Hosting ที่รองรับ DNSSEC
ไม่ใช่ Hosting ทุกเจ้าที่รองรับ DNSSEC ในตัวของ Name Server เอง บางเจ้าต้องใช้ DNS Provider ภายนอกเช่น Cloudflare หรือ NS1 ที่รองรับ DNSSEC แทน ถามผู้ให้บริการของคุณก่อนว่า DNS ที่ให้มารองรับ DNSSEC ไหม
Not every hosting provider supports DNSSEC on their name servers. If yours does not, you can transfer DNS management to a DNSSEC-capable provider such as Cloudflare or NS1 and then submit the DS record to your registrar. Hosting with built-in DNSSEC support is preferable as it simplifies management. AsiaGB.com provides hosting with SSD storage, DirectAdmin, and 24-hour Thai-language support.
- ถาม Hosting ว่า Name Server รองรับ DNSSEC ไหม
- ถ้าไม่รองรับ: ย้าย DNS ไปใช้ Cloudflare DNS (ฟรี, รองรับ DNSSEC)
- AsiaGB.com: Hosting คุณภาพสูง SSD, DirectAdmin, ทีม Support ภาษาไทย 24 ชม.
- ตรวจสอบ DNSSEC Status: dnsxray.com/dnssec.php