What it is¶
delv (Domain Entity Lookup and Validation) ships alongside dig in the same bind-utils/dnsutils package. Where dig +dnssec shows you the DNSSEC records in a response, delv actually performs the validation — walking the chain of trust from a trust anchor down to the record you asked for — and tells you plainly whether the answer is secure, insecure, or bogus.
Basic usage¶
delv example.com # validate and resolve A record
delv example.com AAAA
delv example.com MX
A validated response ends with a line like:
; fully validated
If validation fails you'll see SERVFAIL and a reason — expired signature, missing RRSIG, broken chain of trust — rather than dig's silence on the matter.
Why reach for this over dig¶
dig +dnssec is for inspecting the DNSSEC records themselves (RRSIG, DNSKEY, DS) when you already know what you're looking at. delv answers the actual yes/no question: can this answer be trusted end-to-end from the root down? It uses the same trust anchors as the system's validating resolver, so it's the right tool when you suspect a zone's DNSSEC signing is broken rather than just wanting to see the raw crypto records.
Useful flags¶
| Flag | Meaning |
|---|---|
+vtrace |
verbose validation trace — every step of the trust-chain walk |
+rtrace |
resolution trace — the referral path taken to resolve the query |
-i |
disable validation (plain non-validating lookup, for comparison) |
-a <file> |
use an alternate trust anchor / key file instead of the system default |
Cheat sheet¶
delv example.com # validate + resolve
delv +vtrace example.com # show the full validation chain
delv -i example.com # same query, validation disabled (for comparison)