Fetches DS and DNSKEY records, computes key tags and reports which DS entries match a published DNSKEY. status is “unsigned” (no DS), “valid” (resolver-validated and at least one DS matches) or “broken”.
Fill in values — the call below updates as you type. Nothing is sent: the API does not currently allow browser requests from this domain (CORS). The API key is not stored.