Zone (*) DNSSEC - Informations Zone : (root)(root) 1 DS RR published • Status: Valid because published2 DNSKEY RR found Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 8, KeyTag 22545, Flags 256
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 01.11.2019, 00:00:00 +, Signature-Inception: 11.10.2019, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : comcom 1 DS RR in the parent zone found 2 RRSIG RR to validate DS RR found RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 31.10.2019, 17:00:00 +, Signature-Inception: 18.10.2019, 16:00:00 +, KeyTag 22545, Signer-Name: (root)
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 22545 used to validate the DS RRSet in the parent zone3 DNSKEY RR found Public Key with Algorithm 8, KeyTag 12163, Flags 256
Public Key with Algorithm 8, KeyTag 17708, Flags 256
Public Key with Algorithm 8, KeyTag 30909, Flags 257 (SEP = Secure Entry Point)
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 02.11.2019, 18:24:21 +, Signature-Inception: 18.10.2019, 18:19:21 +, KeyTag 30909, Signer-Name: com
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 30909 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 30909, DigestType 2 and Digest "4tPJFvbe6scylOgmj7WIUESoM/xUWViPSpGEz8QaV2Y=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : macaos.commacaos.com 1 DS RR in the parent zone found 2 RRSIG RR to validate DS RR found RRSIG-Owner macaos.com., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 25.10.2019, 04:56:25 +, Signature-Inception: 18.10.2019, 03:46:25 +, KeyTag 12163, Signer-Name: com
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 12163 used to validate the DS RRSet in the parent zone3 DNSKEY RR found Public Key with Algorithm 13, KeyTag 32277, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 13, KeyTag 42681, Flags 256
Public Key with Algorithm 13, KeyTag 52850, Flags 256
3 RRSIG RR to validate DNSKEY RR found RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 32277, Signer-Name: macaos.com
RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 42681, Signer-Name: macaos.com
RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 52850, Signer-Name: macaos.com
• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 32277 used to validate the DNSKEY RRSet• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 42681 used to validate the DNSKEY RRSet• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 52850 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 32277, DigestType 2 and Digest "QSksyvlUfKpKFcJ0UEHOnEajITDClZURv602E9K5YnM=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneRRSIG Type 1 validates the A - Result: 193.212.5.118 Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 42681, Signer-Name: macaos.com
RRSIG Type 1 validates the A - Result: 193.212.5.118 Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 42681, Signer-Name: macaos.com
RRSIG Type 16 validates the TXT - Result: v=spf1 a mx ip4:193.212.5.112/29 ip6:2001:4610:20::/48 ~all Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 42681, Signer-Name: macaos.com
RRSIG Type 16 validates the TXT - Result: v=spf1 a mx ip4:193.212.5.112/29 ip6:2001:4610:20::/48 ~all Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 42681, Signer-Name: macaos.com
RRSIG Type 28 validates the AAAA - Result: 2001:4610:0020:000A:0192:0168:0005:0118 Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 42681, Signer-Name: macaos.com
RRSIG Type 28 validates the AAAA - Result: 2001:4610:0020:000A:0192:0168:0005:0118 Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 42681, Signer-Name: macaos.com
RRSIG Type 28 validates the AAAA - Result: 2001:4610:0020:000A:0192:0168:0005:0118 Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 28 validates the AAAA - Result: 2001:4610:0020:000A:0192:0168:0005:0118 Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 16 validates the TXT - Result: v=spf1 a mx ip4:193.212.5.112/29 ip6:2001:4610:20::/48 ~all Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 16 validates the TXT - Result: v=spf1 a mx ip4:193.212.5.112/29 ip6:2001:4610:20::/48 ~all Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 1 validates the A - Result: 193.212.5.118 Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 1 validates the A - Result: 193.212.5.118 Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 50, expiration 2019-11-16 13:56:07 + validates the NSEC3 RR that proves the not-existence of the CNAME RR. Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, DNSKEY, NSEC3PARAM
RRSIG Type 50, expiration 2019-11-16 13:56:07 + validates the NSEC3 RR that proves the not-existence of the TLSA RR. Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, DNSKEY, NSEC3PARAM
RRSIG Type 50, expiration 2019-11-16 13:56:07 + validates the NSEC3 RR that proves the not-existence of the TLSA RR. Bitmap: A, AAAA, RRSIG
RRSIG Type 50, expiration 2019-11-16 13:56:07 + validates the NSEC3 RR that proves the not-existence of the CAA RR. Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, DNSKEY, NSEC3PARAM
Zone : www.macaos.comwww.macaos.com 0 DS RR in the parent zone found Zone : (root)(root) 1 DS RR published • Status: Valid because published2 DNSKEY RR found Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 8, KeyTag 22545, Flags 256
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 01.11.2019, 00:00:00 +, Signature-Inception: 11.10.2019, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : comcom 1 DS RR in the parent zone found 2 RRSIG RR to validate DS RR found RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 31.10.2019, 17:00:00 +, Signature-Inception: 18.10.2019, 16:00:00 +, KeyTag 22545, Signer-Name: (root)
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 22545 used to validate the DS RRSet in the parent zone3 DNSKEY RR found Public Key with Algorithm 8, KeyTag 12163, Flags 256
Public Key with Algorithm 8, KeyTag 17708, Flags 256
Public Key with Algorithm 8, KeyTag 30909, Flags 257 (SEP = Secure Entry Point)
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 02.11.2019, 18:24:21 +, Signature-Inception: 18.10.2019, 18:19:21 +, KeyTag 30909, Signer-Name: com
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 30909 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 30909, DigestType 2 and Digest "4tPJFvbe6scylOgmj7WIUESoM/xUWViPSpGEz8QaV2Y=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : macaos.commacaos.com 1 DS RR in the parent zone found 2 RRSIG RR to validate DS RR found RRSIG-Owner macaos.com., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 25.10.2019, 04:56:25 +, Signature-Inception: 18.10.2019, 03:46:25 +, KeyTag 12163, Signer-Name: com
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 12163 used to validate the DS RRSet in the parent zone3 DNSKEY RR found Public Key with Algorithm 13, KeyTag 32277, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 13, KeyTag 42681, Flags 256
Public Key with Algorithm 13, KeyTag 52850, Flags 256
3 RRSIG RR to validate DNSKEY RR found RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 32277, Signer-Name: macaos.com
RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 42681, Signer-Name: macaos.com
RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 52850, Signer-Name: macaos.com
• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 32277 used to validate the DNSKEY RRSet• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 42681 used to validate the DNSKEY RRSet• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 52850 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 32277, DigestType 2 and Digest "QSksyvlUfKpKFcJ0UEHOnEajITDClZURv602E9K5YnM=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : dmz.macaos.comdmz.macaos.com 0 DS RR in the parent zone found DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "m9maqb1fmbahh538j06nu1e0oou2b3ha" between the hashed NSEC3-owner "m9maqb1fmbahh538j06nu1e0oou2b3ha" and the hashed NextOwner "qbrolqn7pvhfm91elr1ceklt9mpov2jn". So the parent zone confirmes the not-existence of a DS RR.Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner m9maqb1fmbahh538j06nu1e0oou2b3ha.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 42681, Signer-Name: macaos.com
DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "m9maqb1fmbahh538j06nu1e0oou2b3ha" between the hashed NSEC3-owner "m9maqb1fmbahh538j06nu1e0oou2b3ha" and the hashed NextOwner "qbrolqn7pvhfm91elr1ceklt9mpov2jn". So the parent zone confirmes the not-existence of a DS RR.Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner m9maqb1fmbahh538j06nu1e0oou2b3ha.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 52850, Signer-Name: macaos.com
0 DNSKEY RR found RRSIG Type 1 validates the A - Result: 193.212.5.118 Validated: RRSIG-Owner dmz.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 42681, Signer-Name: macaos.com
RRSIG Type 1 validates the A - Result: 193.212.5.118 Validated: RRSIG-Owner dmz.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 42681, Signer-Name: macaos.com
RRSIG Type 28 validates the AAAA - Result: 2001:4610:0020:000A:0192:0168:0005:0118 Validated: RRSIG-Owner dmz.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 42681, Signer-Name: macaos.com
RRSIG Type 28 validates the AAAA - Result: 2001:4610:0020:000A:0192:0168:0005:0118 Validated: RRSIG-Owner dmz.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 42681, Signer-Name: macaos.com
RRSIG Type 28 validates the AAAA - Result: 2001:4610:0020:000A:0192:0168:0005:0118 Validated: RRSIG-Owner dmz.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 28 validates the AAAA - Result: 2001:4610:0020:000A:0192:0168:0005:0118 Validated: RRSIG-Owner dmz.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 1 validates the A - Result: 193.212.5.118 Validated: RRSIG-Owner dmz.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 1 validates the A - Result: 193.212.5.118 Validated: RRSIG-Owner dmz.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 16.11.2019, 13:56:07 +, Signature-Inception: 17.10.2019, 13:56:07 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 50, expiration 2019-11-16 13:56:07 + validates the NSEC3 RR that proves the not-existence of the CNAME RR. Bitmap: A, AAAA, RRSIG
RRSIG Type 50, expiration 2019-11-16 13:56:07 + validates the NSEC3 RR that proves the not-existence of the TXT RR. Bitmap: A, AAAA, RRSIG
RRSIG Type 50, expiration 2019-11-16 13:56:07 + validates the NSEC3 RR that proves the not-existence of the TLSA RR. Bitmap: A, AAAA, RRSIG
RRSIG Type 50, expiration 2019-11-16 13:56:07 + validates the NSEC3 RR that proves the not-existence of the CAA RR. Bitmap: A, AAAA, RRSIG