Check · Domain & email identity · default severity low
Signed DNS (DNSSEC)
What Kavach checks
DNSSEC cryptographically signs your DNS so answers can't be forged.
Why it matters
Without DNSSEC, an attacker who poisons DNS can silently send your visitors to a server they control.
How an attacker uses it
- Attacker poisons a DNS resolver with a fake answer for your domain.
- Unsigned DNS can't prove the real answer, so the fake is trusted.
How to fix it
Enable DNSSEC at your DNS host / domain registrar.
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.