DNSSEC cryptographically signs DNS responses so attackers can't forge them. This tool checks for the DS record at the parent and the DNSKEY in the zone — both are needed for a valid chain of trust.