Andrew Mercer
on this page

What it is

delv (Domain Entity Lookup and Validation) ships alongside dig in the same bind-utils/dnsutils package. Where dig +dnssec shows you the DNSSEC records in a response, delv actually performs the validation — walking the chain of trust from a trust anchor down to the record you asked for — and tells you plainly whether the answer is secure, insecure, or bogus.

Basic usage

delv example.com                 # validate and resolve A record
delv example.com AAAA
delv example.com MX

A validated response ends with a line like:

; fully validated

If validation fails you'll see SERVFAIL and a reason — expired signature, missing RRSIG, broken chain of trust — rather than dig's silence on the matter.

Why reach for this over dig

dig +dnssec is for inspecting the DNSSEC records themselves (RRSIG, DNSKEY, DS) when you already know what you're looking at. delv answers the actual yes/no question: can this answer be trusted end-to-end from the root down? It uses the same trust anchors as the system's validating resolver, so it's the right tool when you suspect a zone's DNSSEC signing is broken rather than just wanting to see the raw crypto records.

Useful flags

Flag Meaning
+vtrace verbose validation trace — every step of the trust-chain walk
+rtrace resolution trace — the referral path taken to resolve the query
-i disable validation (plain non-validating lookup, for comparison)
-a <file> use an alternate trust anchor / key file instead of the system default

Cheat sheet

delv example.com                 # validate + resolve
delv +vtrace example.com         # show the full validation chain
delv -i example.com              # same query, validation disabled (for comparison)