Zone (*) | DNSSEC - Informations |
---|
|
Zone: (root)
|
(root)
| 1 DS RR published
|
|
|
| DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0= |
|
|
| • Status: Valid because published
|
|
|
| 2 DNSKEY RR found
|
|
|
| Public Key with Algorithm 8, KeyTag 20038, Flags 256 |
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point) |
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 20.09.2024, 00:00:00 +, Signature-Inception: 30.08.2024, 00:00:00 +, KeyTag 20326, Signer-Name: (root) |
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
Zone: org
|
org
| 1 DS RR in the parent zone found
|
|
|
| DS with Algorithm 8, KeyTag 26974, DigestType 2 and Digest T+3ilMU/Q4oVjEHTlInNeKhr6w2KCur/FHRcDRbh3jI= |
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
| RRSIG-Owner org., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 17.09.2024, 17:00:00 +, Signature-Inception: 04.09.2024, 16:00:00 +, KeyTag 20038, Signer-Name: (root) |
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20038 used to validate the DS RRSet in the parent zone
|
|
|
| 3 DNSKEY RR found
|
|
|
| Public Key with Algorithm 8, KeyTag 23064, Flags 256 |
|
|
| Public Key with Algorithm 8, KeyTag 26974, Flags 257 (SEP = Secure Entry Point) |
|
|
| Public Key with Algorithm 8, KeyTag 54228, Flags 256 |
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
| RRSIG-Owner org., Algorithm: 8, 1 Labels, original TTL: 3600 sec, Signature-expiration: 22.09.2024, 15:21:48 +, Signature-Inception: 01.09.2024, 14:21:48 +, KeyTag 26974, Signer-Name: org |
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 26974 used to validate the DNSKEY RRSet
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 26974, DigestType 2 and Digest "T+3ilMU/Q4oVjEHTlInNeKhr6w2KCur/FHRcDRbh3jI=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
Zone: antopie.org
|
antopie.org
| 1 DS RR in the parent zone found
|
|
|
| DS with Algorithm 8, KeyTag 56854, DigestType 2 and Digest 4S1fX2ohHJeVAKuVioMYTTfI+ogMdjJi2z7go3kHd3k= |
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
| RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 22.09.2024, 15:21:48 +, Signature-Inception: 01.09.2024, 14:21:48 +, KeyTag 23064, Signer-Name: org |
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 23064 used to validate the DS RRSet in the parent zone
|
|
|
| 3 DNSKEY RR found
|
|
|
| Public Key with Algorithm 8, KeyTag 3916, Flags 256 |
|
|
| Public Key with Algorithm 8, KeyTag 56854, Flags 257 (SEP = Secure Entry Point) |
|
|
| Public Key with Algorithm 8, KeyTag 58330, Flags 256 |
|
|
| 3 RRSIG RR to validate DNSKEY RR found
|
|
|
| RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 10800 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 3916, Signer-Name: antopie.org |
|
|
| RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 10800 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 56854, Signer-Name: antopie.org |
|
|
| RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 10800 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 58330, Signer-Name: antopie.org |
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 3916 used to validate the DNSKEY RRSet
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 56854 used to validate the DNSKEY RRSet
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 58330 used to validate the DNSKEY RRSet
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 56854, DigestType 2 and Digest "4S1fX2ohHJeVAKuVioMYTTfI+ogMdjJi2z7go3kHd3k=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
| RRSIG Type 1 validates the A - Result: 78.194.59.118
Validated: RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 21600 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 3916, Signer-Name: antopie.org |
|
|
| RRSIG Type 1 validates the A - Result: 78.194.59.118
Validated: RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 21600 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 3916, Signer-Name: antopie.org |
|
|
| RRSIG Type 16 validates the TXT - Result: v=spf1 a mx -all
Validated: RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 3916, Signer-Name: antopie.org |
|
|
| RRSIG Type 16 validates the TXT - Result: v=spf1 a mx -all
Validated: RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 3916, Signer-Name: antopie.org |
|
|
| RRSIG Type 28 validates the AAAA - Result: 2A01:0E34:EC23:B760:ACAB:0003:0003:0003
Validated: RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 21600 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 3916, Signer-Name: antopie.org |
|
|
| RRSIG Type 28 validates the AAAA - Result: 2A01:0E34:EC23:B760:ACAB:0003:0003:0003
Validated: RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 21600 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 3916, Signer-Name: antopie.org |
|
|
| RRSIG Type 52 validates the TLSA - Result (_443._tcp.antopie.org): _443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 025490860b498ab73c6a12f27a49ad5fe230fafe3ac8f6112c9b7d0aad46941d
_443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 2bbad93ab5c79279ec121507f272cbe0c6647a3aae52e22f388afab426b4adba
_443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 6ddac18698f7f1f7e1c69b9bce420d974ac6f94ca8b2c761701623f99c767dc7
_443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 919c0df7a787b597ed056ace654b1de9c0387acf349f73734a4fd7b58cf612a4
_443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: f1647a5ee3efac54c892e930584fe47979b7acd1c76c1271bca1c5076d869888
Validated: RRSIG-Owner _letsencrypt._dane.antopie.org., Algorithm: 8, 4 Labels, original TTL: 86400 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 3916, Signer-Name: antopie.org |
|
|
| RRSIG Type 52 validates the TLSA - Result (_443._tcp.antopie.org): _443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 025490860b498ab73c6a12f27a49ad5fe230fafe3ac8f6112c9b7d0aad46941d
_443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 2bbad93ab5c79279ec121507f272cbe0c6647a3aae52e22f388afab426b4adba
_443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 6ddac18698f7f1f7e1c69b9bce420d974ac6f94ca8b2c761701623f99c767dc7
_443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 919c0df7a787b597ed056ace654b1de9c0387acf349f73734a4fd7b58cf612a4
_443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: f1647a5ee3efac54c892e930584fe47979b7acd1c76c1271bca1c5076d869888
Validated: RRSIG-Owner _letsencrypt._dane.antopie.org., Algorithm: 8, 4 Labels, original TTL: 86400 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 3916, Signer-Name: antopie.org |
|
|
| RRSIG Type 5 validates the TLSA - Result (_443._tcp.antopie.org): _letsencrypt._dane.antopie.org. That's a CNAME answer
Validated: RRSIG-Owner _443._tcp.antopie.org., Algorithm: 8, 4 Labels, original TTL: 86400 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 3916, Signer-Name: antopie.org |
|
|
| RRSIG Type 5 validates the TLSA - Result (_443._tcp.antopie.org): _letsencrypt._dane.antopie.org. That's a CNAME answer
Validated: RRSIG-Owner _443._tcp.antopie.org., Algorithm: 8, 4 Labels, original TTL: 86400 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 3916, Signer-Name: antopie.org |
|
|
| RRSIG Type 257 validates the CAA - Result: 5|issueletsencrypt.org
Validated: RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 3916, Signer-Name: antopie.org |
|
|
| RRSIG Type 257 validates the CAA - Result: 5|issueletsencrypt.org
Validated: RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 3916, Signer-Name: antopie.org |
|
|
| RRSIG Type 1 validates the A - Result: 78.194.59.118
Validated: RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 21600 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 58330, Signer-Name: antopie.org |
|
|
| RRSIG Type 1 validates the A - Result: 78.194.59.118
Validated: RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 21600 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 58330, Signer-Name: antopie.org |
|
|
| RRSIG Type 16 validates the TXT - Result: v=spf1 a mx -all
Validated: RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 58330, Signer-Name: antopie.org |
|
|
| RRSIG Type 16 validates the TXT - Result: v=spf1 a mx -all
Validated: RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 58330, Signer-Name: antopie.org |
|
|
| RRSIG Type 28 validates the AAAA - Result: 2A01:0E34:EC23:B760:ACAB:0003:0003:0003
Validated: RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 21600 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 58330, Signer-Name: antopie.org |
|
|
| RRSIG Type 28 validates the AAAA - Result: 2A01:0E34:EC23:B760:ACAB:0003:0003:0003
Validated: RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 21600 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 58330, Signer-Name: antopie.org |
|
|
| RRSIG Type 52 validates the TLSA - Result (_443._tcp.antopie.org): _443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 025490860b498ab73c6a12f27a49ad5fe230fafe3ac8f6112c9b7d0aad46941d
_443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 2bbad93ab5c79279ec121507f272cbe0c6647a3aae52e22f388afab426b4adba
_443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 6ddac18698f7f1f7e1c69b9bce420d974ac6f94ca8b2c761701623f99c767dc7
_443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 919c0df7a787b597ed056ace654b1de9c0387acf349f73734a4fd7b58cf612a4
_443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: f1647a5ee3efac54c892e930584fe47979b7acd1c76c1271bca1c5076d869888
Validated: RRSIG-Owner _letsencrypt._dane.antopie.org., Algorithm: 8, 4 Labels, original TTL: 86400 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 58330, Signer-Name: antopie.org |
|
|
| RRSIG Type 52 validates the TLSA - Result (_443._tcp.antopie.org): _443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 025490860b498ab73c6a12f27a49ad5fe230fafe3ac8f6112c9b7d0aad46941d
_443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 2bbad93ab5c79279ec121507f272cbe0c6647a3aae52e22f388afab426b4adba
_443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 6ddac18698f7f1f7e1c69b9bce420d974ac6f94ca8b2c761701623f99c767dc7
_443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 919c0df7a787b597ed056ace654b1de9c0387acf349f73734a4fd7b58cf612a4
_443._tcp.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: f1647a5ee3efac54c892e930584fe47979b7acd1c76c1271bca1c5076d869888
Validated: RRSIG-Owner _letsencrypt._dane.antopie.org., Algorithm: 8, 4 Labels, original TTL: 86400 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 58330, Signer-Name: antopie.org |
|
|
| RRSIG Type 5 validates the TLSA - Result (_443._tcp.antopie.org): _letsencrypt._dane.antopie.org. That's a CNAME answer
Validated: RRSIG-Owner _443._tcp.antopie.org., Algorithm: 8, 4 Labels, original TTL: 86400 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 58330, Signer-Name: antopie.org |
|
|
| RRSIG Type 5 validates the TLSA - Result (_443._tcp.antopie.org): _letsencrypt._dane.antopie.org. That's a CNAME answer
Validated: RRSIG-Owner _443._tcp.antopie.org., Algorithm: 8, 4 Labels, original TTL: 86400 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 58330, Signer-Name: antopie.org |
|
|
| RRSIG Type 257 validates the CAA - Result: 5|issueletsencrypt.org
Validated: RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 58330, Signer-Name: antopie.org |
|
|
| RRSIG Type 257 validates the CAA - Result: 5|issueletsencrypt.org
Validated: RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 58330, Signer-Name: antopie.org |
|
|
| CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "obksl9rhfo8v43clr7b551m2upglm1o5" equal the hashed NSEC3-owner "obksl9rhfo8v43clr7b551m2upglm1o5" and the hashed NextOwner "od00hiundp8mlbamomf1avjanm2nkvj6". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, DNSKEY, NSEC3PARAM, CAA Validated: RRSIG-Owner obksl9rhfo8v43clr7b551m2upglm1o5.antopie.org., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 58330, Signer-Name: antopie.org |
|
|
| CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "obksl9rhfo8v43clr7b551m2upglm1o5" equal the hashed NSEC3-owner "obksl9rhfo8v43clr7b551m2upglm1o5" and the hashed NextOwner "od00hiundp8mlbamomf1avjanm2nkvj6". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, DNSKEY, NSEC3PARAM, CAA Validated: RRSIG-Owner obksl9rhfo8v43clr7b551m2upglm1o5.antopie.org., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 58330, Signer-Name: antopie.org |
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
Zone: www.antopie.org
|
www.antopie.org
| 0 DS RR in the parent zone found
|
|
|
| DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "adl58uspsgmv9nmj6ov4p4sdru4pp6kh" between the hashed NSEC3-owner "9v5c9ufhjc8jcnmumhk31k5j1dfmou36" and the hashed NextOwner "akrjpr4781dpl02hdgb8re7b8aeckn64". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: CNAME, RRSIG Validated: RRSIG-Owner 9v5c9ufhjc8jcnmumhk31k5j1dfmou36.antopie.org., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 3916, Signer-Name: antopie.org |
|
|
| DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "adl58uspsgmv9nmj6ov4p4sdru4pp6kh" between the hashed NSEC3-owner "9v5c9ufhjc8jcnmumhk31k5j1dfmou36" and the hashed NextOwner "akrjpr4781dpl02hdgb8re7b8aeckn64". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: CNAME, RRSIG Validated: RRSIG-Owner 9v5c9ufhjc8jcnmumhk31k5j1dfmou36.antopie.org., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 58330, Signer-Name: antopie.org |
|
|
| DS-Query in the parent zone sends valid NSEC3 RR with the Hash "obksl9rhfo8v43clr7b551m2upglm1o5" as Owner. That's the Hash of "antopie.org" with the NextHashedOwnerName "od00hiundp8mlbamomf1avjanm2nkvj6". So that domain name is the Closest Encloser of "www.antopie.org". Opt-Out: False.
Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, DNSKEY, NSEC3PARAM, CAA Validated: RRSIG-Owner obksl9rhfo8v43clr7b551m2upglm1o5.antopie.org., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 3916, Signer-Name: antopie.org |
|
|
| DS-Query in the parent zone sends valid NSEC3 RR with the Hash "obksl9rhfo8v43clr7b551m2upglm1o5" as Owner. That's the Hash of "antopie.org" with the NextHashedOwnerName "od00hiundp8mlbamomf1avjanm2nkvj6". So that domain name is the Closest Encloser of "www.antopie.org". Opt-Out: False.
Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, DNSKEY, NSEC3PARAM, CAA Validated: RRSIG-Owner obksl9rhfo8v43clr7b551m2upglm1o5.antopie.org., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 58330, Signer-Name: antopie.org |
|
|
| The ClosestEncloser says, that "*.antopie.org" with the Hash "jc0icu9rtfchd03d25pjr0s14qih9v43" is a possible Wildcard of the DS Query Name. But the DS-Query in the parent zone sends a valid NSEC3 RR With the owner "imdnou1rlq2ql65c6krh6mhhun82rp2i" and the Next Owner "jf7tlfh28ehoeeu4raat559e3smsnoq7", so the Hash of the wildcard is between these hashes. So that NSEC3 proves the Not-existence of that wildcard expansion. Opt-Out: False.
Bitmap: CNAME, RRSIG Validated: RRSIG-Owner imdnou1rlq2ql65c6krh6mhhun82rp2i.antopie.org., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 3916, Signer-Name: antopie.org |
|
|
| The ClosestEncloser says, that "*.antopie.org" with the Hash "jc0icu9rtfchd03d25pjr0s14qih9v43" is a possible Wildcard of the DS Query Name. But the DS-Query in the parent zone sends a valid NSEC3 RR With the owner "imdnou1rlq2ql65c6krh6mhhun82rp2i" and the Next Owner "jf7tlfh28ehoeeu4raat559e3smsnoq7", so the Hash of the wildcard is between these hashes. So that NSEC3 proves the Not-existence of that wildcard expansion. Opt-Out: False.
Bitmap: CNAME, RRSIG Validated: RRSIG-Owner imdnou1rlq2ql65c6krh6mhhun82rp2i.antopie.org., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 03.10.2024, 09:23:21 +, Signature-Inception: 03.09.2024, 09:23:21 +, KeyTag 58330, Signer-Name: antopie.org |