Zone (*) DNSSEC - Informations Zone : (root)(root) 1 DS RR published • Status: Valid because published2 DNSKEY RR found Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 8, KeyTag 33853, Flags 256
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 21.02.2020, 00:00:00 +, Signature-Inception: 31.01.2020, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : comcom 1 DS RR in the parent zone found 2 RRSIG RR to validate DS RR found RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 13.02.2020, 05:00:00 +, Signature-Inception: 31.01.2020, 04:00:00 +, KeyTag 33853, Signer-Name: (root)
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 33853 used to validate the DS RRSet in the parent zone2 DNSKEY RR found Public Key with Algorithm 8, KeyTag 30909, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 8, KeyTag 56311, Flags 256
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 10.02.2020, 19:24:21 +, Signature-Inception: 26.01.2020, 19:19:21 +, KeyTag 30909, Signer-Name: com
RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 10.02.2020, 19:24:21 +, Signature-Inception: 26.01.2020, 19:19:21 +, KeyTag 30909, Signer-Name: com
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 30909 used to validate the DNSKEY RRSet• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 30909 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 30909, DigestType 2 and Digest "4tPJFvbe6scylOgmj7WIUESoM/xUWViPSpGEz8QaV2Y=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : macaos.commacaos.com 1 DS RR in the parent zone found 2 RRSIG RR to validate DS RR found RRSIG-Owner macaos.com., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 06.02.2020, 06:50:03 +, Signature-Inception: 30.01.2020, 05:40:03 +, KeyTag 56311, Signer-Name: com
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 56311 used to validate the DS RRSet in the parent zone3 DNSKEY RR found Public Key with Algorithm 13, KeyTag 7970, Flags 256
Public Key with Algorithm 13, KeyTag 26985, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 13, KeyTag 52850, Flags 256
3 RRSIG RR to validate DNSKEY RR found RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 7970, Signer-Name: macaos.com
RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 26985, Signer-Name: macaos.com
RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 52850, Signer-Name: macaos.com
• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 7970 used to validate the DNSKEY RRSet• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 26985 used to validate the DNSKEY RRSet• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 52850 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 26985, DigestType 2 and Digest "MXFqedYdQbc+6OlRO/1iYXMlzAQ4uRXGoOuM2Y4l200=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneRRSIG Type 1 validates the A - Result: 193.212.5.118 Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 7970, Signer-Name: macaos.com
RRSIG Type 1 validates the A - Result: 193.212.5.118 Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 7970, Signer-Name: macaos.com
RRSIG Type 16 validates the TXT - Result: v=spf1 a mx ip4:193.212.5.112/29 ip6:2001:4610:20::/48 ~all Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 7970, Signer-Name: macaos.com
RRSIG Type 16 validates the TXT - Result: v=spf1 a mx ip4:193.212.5.112/29 ip6:2001:4610:20::/48 ~all Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 7970, Signer-Name: macaos.com
RRSIG Type 28 validates the AAAA - Result: 2001:4610:0020:000A:0192:0168:0005:0118 Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 7970, Signer-Name: macaos.com
RRSIG Type 28 validates the AAAA - Result: 2001:4610:0020:000A:0192:0168:0005:0118 Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 7970, Signer-Name: macaos.com
RRSIG Type 28 validates the AAAA - Result: 2001:4610:0020:000A:0192:0168:0005:0118 Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 28 validates the AAAA - Result: 2001:4610:0020:000A:0192:0168:0005:0118 Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 16 validates the TXT - Result: v=spf1 a mx ip4:193.212.5.112/29 ip6:2001:4610:20::/48 ~all Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 16 validates the TXT - Result: v=spf1 a mx ip4:193.212.5.112/29 ip6:2001:4610:20::/48 ~all Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 1 validates the A - Result: 193.212.5.118 Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 1 validates the A - Result: 193.212.5.118 Validated: RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 50, expiration 2020-02-29 17:17:01 + validates the NSEC3 RR that proves the not-existence of the CNAME RR. Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, DNSKEY, NSEC3PARAM
RRSIG Type 50, expiration 2020-02-29 17:17:01 + validates the NSEC3 RR that proves the not-existence of the TLSA RR. Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, DNSKEY, NSEC3PARAM
RRSIG Type 50, expiration 2020-02-29 17:17:01 + validates the NSEC3 RR that proves the not-existence of the CAA RR. Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, DNSKEY, NSEC3PARAM
Zone : www.macaos.comwww.macaos.com 0 DS RR in the parent zone found Zone : (root)(root) 1 DS RR published • Status: Valid because published2 DNSKEY RR found Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 8, KeyTag 33853, Flags 256
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 21.02.2020, 00:00:00 +, Signature-Inception: 31.01.2020, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : comcom 1 DS RR in the parent zone found 2 RRSIG RR to validate DS RR found RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 13.02.2020, 05:00:00 +, Signature-Inception: 31.01.2020, 04:00:00 +, KeyTag 33853, Signer-Name: (root)
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 33853 used to validate the DS RRSet in the parent zone2 DNSKEY RR found Public Key with Algorithm 8, KeyTag 30909, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 8, KeyTag 56311, Flags 256
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 10.02.2020, 19:24:21 +, Signature-Inception: 26.01.2020, 19:19:21 +, KeyTag 30909, Signer-Name: com
RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 10.02.2020, 19:24:21 +, Signature-Inception: 26.01.2020, 19:19:21 +, KeyTag 30909, Signer-Name: com
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 30909 used to validate the DNSKEY RRSet• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 30909 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 30909, DigestType 2 and Digest "4tPJFvbe6scylOgmj7WIUESoM/xUWViPSpGEz8QaV2Y=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : macaos.commacaos.com 1 DS RR in the parent zone found 2 RRSIG RR to validate DS RR found RRSIG-Owner macaos.com., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 06.02.2020, 06:50:03 +, Signature-Inception: 30.01.2020, 05:40:03 +, KeyTag 56311, Signer-Name: com
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 56311 used to validate the DS RRSet in the parent zone3 DNSKEY RR found Public Key with Algorithm 13, KeyTag 7970, Flags 256
Public Key with Algorithm 13, KeyTag 26985, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 13, KeyTag 52850, Flags 256
3 RRSIG RR to validate DNSKEY RR found RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 7970, Signer-Name: macaos.com
RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 26985, Signer-Name: macaos.com
RRSIG-Owner macaos.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 52850, Signer-Name: macaos.com
• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 7970 used to validate the DNSKEY RRSet• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 26985 used to validate the DNSKEY RRSet• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 52850 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 26985, DigestType 2 and Digest "MXFqedYdQbc+6OlRO/1iYXMlzAQ4uRXGoOuM2Y4l200=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : dmz.macaos.comdmz.macaos.com 0 DS RR in the parent zone found DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "2p33v6k52h9rb2qho8n2phbuv77d0343" between the hashed NSEC3-owner "2p33v6k52h9rb2qho8n2phbuv77d0343" and the hashed NextOwner "3ru0l5rc07vc76elmge2mel2l6hrn0nc". So the parent zone confirmes the not-existence of a DS RR.Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner 2p33v6k52h9rb2qho8n2phbuv77d0343.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 7970, Signer-Name: macaos.com
DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "2p33v6k52h9rb2qho8n2phbuv77d0343" between the hashed NSEC3-owner "2p33v6k52h9rb2qho8n2phbuv77d0343" and the hashed NextOwner "3ru0l5rc07vc76elmge2mel2l6hrn0nc". So the parent zone confirmes the not-existence of a DS RR.Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner 2p33v6k52h9rb2qho8n2phbuv77d0343.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 52850, Signer-Name: macaos.com
0 DNSKEY RR found RRSIG Type 28 validates the AAAA - Result: 2001:4610:0020:000A:0192:0168:0005:0118 Validated: RRSIG-Owner dmz.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 7970, Signer-Name: macaos.com
RRSIG Type 28 validates the AAAA - Result: 2001:4610:0020:000A:0192:0168:0005:0118 Validated: RRSIG-Owner dmz.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 7970, Signer-Name: macaos.com
RRSIG Type 1 validates the A - Result: 193.212.5.118 Validated: RRSIG-Owner dmz.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 7970, Signer-Name: macaos.com
RRSIG Type 1 validates the A - Result: 193.212.5.118 Validated: RRSIG-Owner dmz.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 7970, Signer-Name: macaos.com
RRSIG Type 1 validates the A - Result: 193.212.5.118 Validated: RRSIG-Owner dmz.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 1 validates the A - Result: 193.212.5.118 Validated: RRSIG-Owner dmz.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 28 validates the AAAA - Result: 2001:4610:0020:000A:0192:0168:0005:0118 Validated: RRSIG-Owner dmz.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 28 validates the AAAA - Result: 2001:4610:0020:000A:0192:0168:0005:0118 Validated: RRSIG-Owner dmz.macaos.com., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 29.02.2020, 17:17:01 +, Signature-Inception: 30.01.2020, 17:17:01 +, KeyTag 52850, Signer-Name: macaos.com
RRSIG Type 50, expiration 2020-02-29 17:17:01 + validates the NSEC3 RR that proves the not-existence of the CNAME RR. Bitmap: A, AAAA, RRSIG
RRSIG Type 50, expiration 2020-02-29 17:17:01 + validates the NSEC3 RR that proves the not-existence of the TXT RR. Bitmap: A, AAAA, RRSIG
RRSIG Type 50, expiration 2020-02-29 17:17:01 + validates the NSEC3 RR that proves the not-existence of the TLSA RR. Bitmap: A, AAAA, RRSIG
RRSIG Type 50, expiration 2020-02-29 17:17:01 + validates the NSEC3 RR that proves the not-existence of the CAA RR. Bitmap: A, AAAA, RRSIG