DNS monitoring

DNSSEC & DANE/TLSA Monitoring

dnssecdanetlsadns securityzone signingdowngrade alertdns monitoring

What it checks

DNS-security monitoring re-checks, on your asset's cadence, whether your DNS zone is DNSSEC-signed (a DNSKEY chain that resolvers can authenticate) and how many signing keys are published, plus whether DANE/TLSA records exist (which pin your TLS certificate at the DNS layer). It builds a posture history over time.

When it alerts

The dangerous change is a zone that was signed going unsigned — a botched nameserver migration, a DS record dropped at the registrar, or a provider change that did not re-sign. That definitive signed→unsigned transition strips origin-authentication from every DNS answer, silently and with no visible outage. Merlonix trips a warning alert on that downgrade and an info recovery when the zone is re-signed. A resolver failure or indeterminate answer is recorded as unknown and never alerts, so a transient DNS blip is not misread as a downgrade.

Reading the result

The asset detail page shows your current signing state (signed / not signed / unknown), the DNSKEY count, and whether DANE is on. Like the other posture checks, it is informational — not folded into a pass/fail score, so the free domain-health tool and the audit report never disagree with it.

Turning it on

Enable Monitor DNS security (DNSSEC / DANE) when you add or edit an asset. It is a $0 deterministic DNS lookup on your existing cadence and is available on every plan. To check your DNSSEC posture instantly with no signup, run the free domain-health scan on the marketing site.

More in DNS monitoring

Try it on your own sites

Point Merlonix at your client domains and watch SSL, DNS, uptime, and vendor status from one dashboard. Start the full workspace free, no credit card.