This site contains affiliate links — we may earn a commission if you sign up through them.

DNSSEC Validator: How to Check Your Domain's Chain of Trust (2026)

DNSSEC Validator: How to Check Your Domain's Chain of Trust (2026)

DNSSEC คืออะไร

DNSSEC (Domain Name System Security Extensions) คือชุดมาตรฐานที่เพิ่มการตรวจสอบความถูกต้องด้วยลายเซ็นดิจิทัลให้กับ DNS ช่วยป้องกันการโจมตีแบบ DNS Cache Poisoning ที่แฮกเกอร์อาจสร้าง DNS Record ปลอมเพื่อเปลี่ยนเส้นทาง Traffic ของผู้ใช้ไปยังเซิร์ฟเวอร์อันตราย

DNSSEC (Domain Name System Security Extensions) is a suite of Internet Engineering Task Force (IETF) specifications that adds cryptographic authentication to DNS responses. Without DNSSEC, an attacker who can poison a resolver's cache can redirect users to malicious servers even when they type the correct domain name.

ทำไม DNSSEC ถึงสำคัญ

ปัญหา DNS Spoofing ไม่ใช่เรื่องเล็กน้อย งานวิจัยของ NIST พบว่า DNS Cache Poisoning Attack ยังเกิดขึ้นในปัจจุบัน โดยเฉพาะบน Resolver ที่ไม่ได้รับการอัปเดต โดเมนที่ไม่มี DNSSEC สามารถถูกโจมตีได้แม้ใช้ HTTPS เพราะ TLS ป้องกัน Transport Layer แต่ไม่ป้องกัน DNS ที่ Resolve ชื่อโดเมนก่อน

DNS spoofing remains a real threat. A resolver cache poisoning attack can redirect users to phishing sites or malicious servers even when they use HTTPS — because TLS secures the transport layer but cannot verify that the DNS resolution step correctly identifies the server. DNSSEC closes this gap by making every DNS response verifiable.

Chain of Trust และ DS Record

DNSSEC ใช้ Chain of Trust ที่เชื่อมจาก Root Zone (Root DNS) ผ่าน TLD Name Server (เช่น .com, .th) ลงมาถึง Authoritative Name Server ของโดเมน ทุก Link ในห่วงโซ่นี้ต้องมีลายเซ็นที่ถูกต้อง

DNSSEC establishes a chain of trust from the DNS root zone down to individual domain zones. The root zone signs delegations to TLD name servers (.com, .th etc.), TLD name servers sign delegations to authoritative name servers for individual domains, and each zone signs its own resource records. Every link in this chain must be valid for DNSSEC validation to succeed.

ตัวอย่าง DS Record:
example.com. 3600 IN DS 12345 8 2 abc123...sha256hash...
ตัวเลข 12345 = Key Tag, 8 = Algorithm (RSA/SHA-256), 2 = Digest Type (SHA-256)

DNSKEY: KSK และ ZSK

DNSKEY Record เก็บ Public Key ที่ใช้ตรวจสอบลายเซ็น DNSSEC แต่ละโดเมนมี DNSKEY อย่างน้อย 2 ตัว: KSK ที่เซ็น DNSKEY Record ด้วยตัวเอง และ ZSK ที่เซ็น Record อื่นทั้งหมดในโซน

Each DNSSEC-enabled zone publishes at least two DNSKEY records. The Key-Signing Key (KSK) has the Zone Key flag set and is used exclusively to sign the DNSKEY RRset — its hash appears in the DS record held by the parent zone. The Zone-Signing Key (ZSK) signs all other records in the zone. This two-key design allows zone operators to rotate ZSKs frequently without updating the DS record at the registrar.

RRSIG: ลายเซ็นดิจิทัลของ DNS Record

RRSIG (Resource Record Signature) คือลายเซ็นดิจิทัลที่แนบมากับทุก Record Set ใน Zone ที่เปิด DNSSEC Validator ที่ Analyze.in.th ตรวจสอบ RRSIG บน SOA Record (ยืนยันว่า Zone มีลายเซ็น) และบน DNSKEY Record (ยืนยัน KSK สามารถเซ็น DNSKEY ได้)

Every resource record set in a DNSSEC-signed zone is accompanied by one or more RRSIG records containing the cryptographic signature over the record set. The Analyze.in.th DNSSEC Validator checks RRSIG records on the SOA (confirming the zone is signed) and on the DNSKEY RRset (confirming the KSK signs the DNSKEY set, completing the chain of trust).

NSEC/NSEC3: Denial of Existence

DNSSEC ต้องสามารถ "ยืนยัน" ว่าไม่มี Record อยู่ได้ด้วย ไม่ใช่แค่ยืนยันว่ามี โดยใช้ NSEC หรือ NSEC3 Record เพื่อ Authenticate คำตอบ NXDOMAIN (Record ไม่มีอยู่)

DNSSEC must also authenticate negative responses — confirming that a record does not exist is just as important as confirming it does. NSEC records create a cryptographically signed linked list of all names in the zone. NSEC3 hashes the names first to prevent zone enumeration (zone walking), making it the preferred choice for privacy-conscious zone operators.

วิธีใช้ DNSSEC Validator ที่ Analyze.in.th

DNSSEC Validator ที่ Analyze.in.th ตรวจสอบ Chain of Trust ทั้งหมดโดยไม่ต้องติดตั้งซอฟต์แวร์ใด ทำงานผ่าน Browser ได้เลย

The Analyze.in.th DNSSEC Validator checks the complete DNSSEC chain of trust for any domain in seconds — no software installation required. It uses a DNSSEC-aware resolver built into the platform to query DS, DNSKEY, and RRSIG records and verify their cryptographic relationships.

  1. เปิด https://dnsxray.com/dnssec.php
  2. พิมพ์ชื่อโดเมนในช่อง เช่น example.com
  3. กด Validate DNSSEC
  4. อ่านผลลัพธ์: สีเขียว = ผ่าน, สีเหลือง = คำเตือน, สีแดง = ล้มเหลว

ผลลัพธ์ที่ได้รวมถึง: DS Record ที่ TLD, DNSKEY (KSK/ZSK พร้อม Key Tag), RRSIG บน SOA และ DNSKEY, การตรวจสอบ DS↔DNSKEY Match, และ NSEC/NSEC3 Status

The result covers: DS record at the TLD parent zone; DNSKEY records (KSK and ZSK with key tags); RRSIG signatures on SOA and DNSKEY; DS-to-DNSKEY key tag match verification; and NSEC/NSEC3 denial-of-existence support.

วิธีเปิด DNSSEC บนโดเมนของคุณ

การเปิด DNSSEC ต้องทำสองส่วน: เปิด DNSSEC ที่ Name Server ของโดเมน และส่ง DS Record ไปยัง Registrar เพื่อให้ TLD บันทึก

Enabling DNSSEC requires action at two levels. First, the authoritative name server must sign the zone and publish DNSKEY records. Second, the DS record (a hash of the KSK) must be submitted to the domain registrar, which publishes it in the parent TLD zone. Both steps must be completed for the chain of trust to form.

Hosting ที่รองรับ DNSSEC

ไม่ใช่ Hosting ทุกเจ้าที่รองรับ DNSSEC ในตัวของ Name Server เอง บางเจ้าต้องใช้ DNS Provider ภายนอกเช่น Cloudflare หรือ NS1 ที่รองรับ DNSSEC แทน ถามผู้ให้บริการของคุณก่อนว่า DNS ที่ให้มารองรับ DNSSEC ไหม

Not every hosting provider supports DNSSEC on their name servers. If yours does not, you can transfer DNS management to a DNSSEC-capable provider such as Cloudflare or NS1 and then submit the DS record to your registrar. Hosting with built-in DNSSEC support is preferable as it simplifies management. AsiaGB.com provides hosting with SSD storage, DirectAdmin, and 24-hour Thai-language support.

RecommendedAsiaGB.com — Web Hosting & VPS we use and recommend. Servers in Thailand and Singapore, SSD storage, DirectAdmin control panel, 24-hour Thai support, 99% uptime.

Editor's choice for Thai web hosting — reliable, affordable, and locally supported.

Visit AsiaGB →

Frequently Asked Questions

DNSSEC ทำให้ DNS ช้าลงไหม
DNSSEC เพิ่ม Overhead เล็กน้อยจาก Signature Verification แต่ Resolver สมัยใหม่ Cache ผลลัพธ์ไว้ ผลกระทบต่อ End User แทบไม่รู้สึก ช้าลงไม่เกิน 1-2ms ในสภาวะปกติ
DNSSEC เป็นสิ่งจำเป็นถ้าใช้ HTTPS แล้วหรือไม่
ยังจำเป็น HTTPS ป้องกัน Transport Layer (ข้อมูลขณะส่ง) แต่ถ้า DNS ถูก Poison ก่อน ผู้ใช้จะถูกนำไปยังเซิร์ฟเวอร์ผิดและอาจได้รับ Certificate ปลอม DNSSEC ป้องกันชั้น DNS ก่อนที่ HTTPS จะเริ่มทำงาน
โดเมน .th ของไทยรองรับ DNSSEC ไหม
รองรับ ผู้จดทะเบียน .th ผ่าน THNIC สามารถเปิด DNSSEC ได้ ต้องติดต่อ Registrar ที่จดโดเมนไว้เพื่อขอ Submit DS Record ไปยัง THNIC
ถ้า DNSSEC ตั้งค่าผิดจะเกิดอะไรขึ้น
โดเมน Resolve ไม่ได้สำหรับ Resolver ที่ Validate DNSSEC (เช่น Google DNS 8.8.8.8, Cloudflare 1.1.1.1) ผู้ใช้จะเห็น "SERVFAIL" ดังนั้นต้องทดสอบก่อน Deploy และมี Monitoring แจ้งเตือนก่อน RRSIG Expire