The RRSIG record (Resource Record Signature) contains the cryptographic signature for a DNS record set. It's the core mechanism that allows DNSSEC to prove that DNS data is authentic and hasn't been modified in transit.
Check RRSIG records for any domain using our free DNS lookup tool.
Look Up RRSIG Records →Every DNS record set in a DNSSEC-signed zone has an associated RRSIG record. The RRSIG contains:
When a resolver receives a DNS response, it verifies the RRSIG using the zone's DNSKEY.
example.com. 3600 IN RRSIG A 13 2 3600 (
20240315000000 20240215000000 12345 example.com.
oJB1W6WNGv...signature... )
| Field | Description | Example |
|---|---|---|
| Type Covered | Record type being signed | A, MX, AAAA, etc. |
| Algorithm | Signing algorithm | 13 (ECDSA) |
| Labels | Number of labels in name | 2 (example.com) |
| Original TTL | TTL used when signing | 3600 |
| Signature Expiration | When signature expires | 20240315000000 |
| Signature Inception | When signature became valid | 20240215000000 |
| Key Tag | Identifier of signing key | 12345 |
| Signer's Name | Zone containing DNSKEY | example.com. |
| Signature | Base64-encoded signature | oJB1W6WNGv... |
RRSIG records have an expiration time. Once expired, the signature is no longer valid and resolvers will reject the data. Key considerations:
# Query with DNSSEC info
dig example.com A +dnssec
# Just the RRSIG records
dig example.com RRSIG
# Validate DNSSEC chain
delv example.com @8.8.8.8
Common issues and solutions:
DNS Explorer tracks RRSIG expiration, validates signature chains, and alerts you before signatures expire.
Start free DNS Explorer trial14-day full-feature trial
Use our DNS Record Finder to look up RRSIG records for any domain.
Look Up RRSIG Records →