정상적으로 DNSSEC 서명 검증이 완료된 경우 응답메세지 flag에 *ad가 표시됩니다.(ad:Authenticated Data) falg중 ad는 검색 도메인에 대한 DNS 응답이 서명 검증 절차를 통과하였음을 의미합니다.
;<<>> DIG 9.9.7-P3 <<>>+dnssec +multi @ 208.255.210.54 test dnssec.safed ns.kr A ;; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 29392 ;; flags: qr rd ra ad: QUERY 1, ANSWER: 0, AUTHORITY: 4, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags: do: udp: 1460 ;; QUESTION SECTION: ;; testdnssec.safedns.kr. IN A ;; AUTHORITY SECTION: testdnssec.safedns.kr. 300 IN SOA ns1.testdnssec.safed ns. kr. domain_manager. safedns.kr. ( 2018031403; serial 1800; refresh (30 minutes) 300 retry (5 minutes) 3600000; expire (5 weeks 6 days 16 hours) 300; minimum (5 minutes) ) testdnssec.safedns.kr. 300 IN RRSIG SOA 7 3 300 ( 20180315013011 20180314003011 26745 testdnssec, safedns. kr. KniN6NVXV/ZQOSTEOFh8s31D25KICaFyL+Jbv9X4/zf9 BqL/LqNEVIE9YCvEjtkVUKEN soD 3LSv+m s8rSvMnGf 09uzWy42oLxCkUInXTnCE21JZUEsduoGJU9JXEhGUgt ZxX31N3GBkm ZJd0uVkUr7YBBm Tp531100HUo-) 143ETRP2B5B7JGPIKS20C17BS3SMLBFH. testdnssec.safedns.kr. 300 IN RRSIG NSEC3 7 4 300 ( 20180315013011 20180314003011 26745 testdnssec. safedns. kr. JQEHm HFDNEY09vWaycX8ZWPLO+FW+0FL+Mh3KN C3WMkt EuOPIMqTWhi2KzS9CHDXRuPzWCBF3AWX23d4Swo7AAmb e7CwPWBMxd+h4e/pnVGQM700C/QGez7zzCoY/yrnn8 8Rvs5yQt5Kqj6F8M/LvGCjo2eMFS3hID 2m RE121=) 143ETRP2B5B7JGP1KS20C17BS3SMLBFH. testdnssec.safedns.kr. 300 IN NSEC3 1 1 350 ( 2K9TB9A30MKEK4IBISO28H0AH1KJVQHB NS SOA RRSIG DNSKEY NSEC3PARAM) ;; Query time: 9m sec ;; #SERVER: 203.255.210.54#53(203.255.210.54) ;; WHEN: Wed Mar 14 10:39:52 KST 2018 ;; MSG SIZE rcvd: 548