This page checks a demonstration identity the way a careful verifier would, live, in your browser. It fetches the identity's key from the website, then asks two independent DNS resolvers for the same key in DNSSEC-signed records, follows the chain of trust back to the root of the DNS, and checks every signature. Nothing is pre-recorded: each step queries the real internet. Choose a scenario, press Verify, and watch where each confirmation comes from.
No single tool is trusted alone. The same identity is checked by independent implementations, and each is responsible for a different protocol layer.
| Protocol layer | Standard | Validated by | Latest result |
|---|---|---|---|
| DNSSEC signatures on every record | RFC 4033–4035 | Google Public DNS and Cloudflare DNS (they return the AD "authenticated data" flag only after checking every RRSIG from the root down) | AD=1 at both, every run of this page |
| Chain of trust links (DS ↔ DNSKEY) | RFC 4034, IANA root anchor | This page: your browser recomputes each delegation's DS digest from the child's key and compares it with the parent | computed live below |
DID ↔ domain binding (URI + TLSA at _did) | draft-carter-high-assurance-dids-with-dns-08 §3; draft-ranjbar-dane-did (3 1 1) | This page; verify_dnssec.mjs (Node) | PASS, all four identities (24 Sept 2026) |
| DID document integrity proof, verified with the DNS-published key | draft-carter §5, §6 step 3; W3C Data Integrity eddsa-jcs-2022 | This page (WebCrypto); verify_dnssec.mjs; Digital Bazaar jsonld-signatures + eddsa-jcs-2022-cryptosuite (verify_diddoc_proof_db.mjs) | PASS, all four; tamper rejected |
| Verifiable Credential | W3C VC Data Model 2.0; eddsa-jcs-2022 and eddsa-rdfc-2022 | This page (jcs); Digital Bazaar @digitalbazaar/vc (verify.mjs --live, both cryptosuites) | verified: true, both suites; tamper rejected |
Assurance per draft-carter §8: Controls 1–8 met (MEDIUM+, with DNSSEC signing). HIGH would need the issuer to hold its own zone-signing keys (Controls 9–10), which Cloudflare-managed DNSSEC doesn't allow. Both IETF drafts are individual submissions, so this is aligned with them, not conformance to a ratified standard. The identities here are demonstrations, not production PrIDs.