Check any DID
Resolve it, read its keys, verify its signature, and test whether its key is anchored in DNSSEC. Everything runs in your browser.
Other organizations:
Show the resolved DID document
What the levels mean
| Level | What it proves |
|---|---|
| 1. Resolves | The identifier is well formed and its DID document can be retrieved, and the document says it belongs to this DID. |
| 2. Usable keys | The document lists at least one public key in a form this checker can read. |
| 3. Signed document | The document carries a Data Integrity proof (eddsa-jcs-2022) that verifies, and hasn't expired. For did:key this is not needed: the identifier is the key. |
| 4. Anchored in DNSSEC | For did:web: the domain publishes the DID and its key in DNSSEC-signed _did records (IETF draft-carter-high-assurance-dids-with-dns). Google and Cloudflare both return the same records, both validate them, the chain of keys links back to the DNS root, and the key on the website matches the key in DNS. The website alone can then no longer lie about who the identity is. |
A Prime Identity (PrID) is built to reach all four levels. Most DIDs in use today stop at level 1 or 2. That doesn't make them invalid; it tells you how much you're trusting the web server that hosts them.
How the check works, and what it trusts
Your browser fetches the DID document directly from its host and asks two public resolvers, Google Public DNS (8.8.8.8) and Cloudflare (1.1.1.1), over DNS-over-HTTPS. Every DNS answer must be DNSSEC-validated by both, and the two must agree record for record. The checker then follows the chain of DNSSEC keys from the IANA root trust anchor down to the identity's zone, and does every signature check itself with your browser's built-in cryptography.
Supported identifiers
did:web: full check, including the DNSSEC anchor. A bare domain is read asdid:web.did:key(Ed25519, P-256, secp256k1, X25519) anddid:jwk: resolved locally from the identifier itself.did:plc: resolved throughplc.directory.- Other methods: not checked here yet; the page links you to the DIF Universal Resolver instead.
Some web servers don't allow browsers to read their DID document from another site (no CORS header). When that happens the page says so. It is a setting on that server, not proof that the DID is invalid.
prdid.com demonstration identities (demo, gestalt, tribernachi, lydian) are demonstrations with throwaway keys, not production PrIDs.