On this page
DNSSEC adds cryptographic validation to DNS. A DS record for a TLD in the root is the parent-side link used to authenticate that TLD's DNSSEC chain. DS presence is a technical fact; it does not mean every domain beneath the TLD is signed.
The chain of trust
DNSSEC allows DNS data to be validated using digital signatures. Validation follows a chain of trust from a configured trust anchor through signed delegations toward the name being queried.
What a DS record says
A DS record is published by the parent zone and identifies a key in the child zone. For a TLD, the parent is the DNS root. Its presence can therefore be used as a deterministic signal that the root contains a DNSSEC delegation for that TLD.
What it does not say
Root DS presence does not prove that every second-level domain beneath the TLD is signed, nor does it measure the operational quality of the TLD's DNS.
DNSSEC is one protocol property. It should not be turned into a broad security or trustworthiness rating.
How to display it
A reference page can show DS present, list the DS parameters published in the root, and link to the authoritative source. Anything more evaluative needs separate evidence.
Primary sources
These are the primary references this guide is designed around. When implementation data disagrees with editorial copy, the primary source wins.