Zone (*) | DNSSEC - Informations |
---|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 3 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 5613, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20038, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 22.07.2024, 00:00:00 +, Signature-Inception: 01.07.2024, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: ch
|
|
ch
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 13, KeyTag 450, DigestType 2 and Digest SZSRPZ/08N+V8IrN8dZhSdhzNo/2wYNsZL36zmJzT6I=
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner ch., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 22.07.2024, 17:00:00 +, Signature-Inception: 09.07.2024, 16:00:00 +, KeyTag 20038, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20038 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 3 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 13, KeyTag 450, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 13, KeyTag 1126, Flags 256
|
|
|
|
|
| Public Key with Algorithm 13, KeyTag 53572, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner ch., Algorithm: 13, 1 Labels, original TTL: 86400 sec, Signature-expiration: 07.08.2024, 10:09:09 +, Signature-Inception: 22.06.2024, 09:09:09 +, KeyTag 450, Signer-Name: ch
|
|
|
|
|
| • Status: Good - Algorithmus 13 and DNSKEY with KeyTag 450 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 450, DigestType 2 and Digest "SZSRPZ/08N+V8IrN8dZhSdhzNo/2wYNsZL36zmJzT6I=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: davidkyburz.ch
|
|
davidkyburz.ch
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 13, KeyTag 49538, DigestType 2 and Digest 46nRzUrkvfAj/jHLGcYbZxQ3d77zmD8qELcS1gMA4SQ=
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner davidkyburz.ch., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 06.08.2024, 09:02:28 +, Signature-Inception: 07.07.2024, 09:01:48 +, KeyTag 1126, Signer-Name: ch
|
|
|
|
|
| • Status: Good - Algorithmus 13 and DNSKEY with KeyTag 1126 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 13, KeyTag 24647, Flags 256
|
|
|
|
|
| Public Key with Algorithm 13, KeyTag 49538, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 2 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner davidkyburz.ch., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.07.2024, 08:47:12 +, Signature-Inception: 08.07.2024, 07:53:29 +, KeyTag 24647, Signer-Name: davidkyburz.ch
|
|
|
|
|
| RRSIG-Owner davidkyburz.ch., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.07.2024, 08:47:12 +, Signature-Inception: 08.07.2024, 07:53:29 +, KeyTag 49538, Signer-Name: davidkyburz.ch
|
|
|
|
|
| • Status: Good - Algorithmus 13 and DNSKEY with KeyTag 24647 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 13 and DNSKEY with KeyTag 49538 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 49538, DigestType 2 and Digest "46nRzUrkvfAj/jHLGcYbZxQ3d77zmD8qELcS1gMA4SQ=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| RRSIG Type 1 validates the A - Result: 172.245.88.197
Validated: RRSIG-Owner davidkyburz.ch., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.07.2024, 07:27:13 +, Signature-Inception: 08.07.2024, 06:43:10 +, KeyTag 24647, Signer-Name: davidkyburz.ch
|
|
|
|
|
| RRSIG Type 16 validates the TXT - Result: v=spf1 include:spf.infomaniak.ch -all
Validated: RRSIG-Owner davidkyburz.ch., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 29.07.2024, 00:17:28 +, Signature-Inception: 07.07.2024, 23:53:32 +, KeyTag 24647, Signer-Name: davidkyburz.ch
|
|
|
|
|
| CNAME-Query sends a valid NSEC RR as result with the query name "davidkyburz.ch" equal the NSEC-owner "davidkyburz.ch" and the NextOwner "_dmarc.davidkyburz.ch". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, RRSIG, NSEC, DNSKEY Validated: RRSIG-Owner davidkyburz.ch., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 30.07.2024, 04:26:50 +, Signature-Inception: 09.07.2024, 03:48:02 +, KeyTag 24647, Signer-Name: davidkyburz.ch
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| AAAA-Query sends a valid NSEC RR as result with the query name "davidkyburz.ch" equal the NSEC-owner "davidkyburz.ch" and the NextOwner "_dmarc.davidkyburz.ch". So the zone confirmes the not-existence of that AAAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, RRSIG, NSEC, DNSKEY Validated: RRSIG-Owner davidkyburz.ch., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 30.07.2024, 04:26:50 +, Signature-Inception: 09.07.2024, 03:48:02 +, KeyTag 24647, Signer-Name: davidkyburz.ch
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TLSA-Query (_443._tcp.davidkyburz.ch) sends a valid NSEC RR as result with the owner name davidkyburz.ch. So that's the Closest Encloser of the query name. TLSA-Query sends a valid NSEC RR as result and covers the Wildcard expansion of the ClosestEncloser with the owner "davidkyburz.ch" and the NextOwner "_dmarc.davidkyburz.ch". So that NSEC confirms the not-existence of the Wildcard expansion.
Bitmap: A, NS, SOA, MX, TXT, RRSIG, NSEC, DNSKEY Validated: RRSIG-Owner davidkyburz.ch., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 30.07.2024, 04:26:50 +, Signature-Inception: 09.07.2024, 03:48:02 +, KeyTag 24647, Signer-Name: davidkyburz.ch
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| TLSA-Query (_443._tcp.davidkyburz.ch) sends a valid NSEC RR as result with the query name "_443._tcp.davidkyburz.ch" between the NSEC-owner "_domainkey.davidkyburz.ch" and the NextOwner "autoconfig.davidkyburz.ch". So the zone confirmes the not-existence of that TLSA RR.TLSA-Query (_443._tcp.davidkyburz.ch) sends a valid NSEC RR as result with the parent Wildcard "*._tcp.davidkyburz.ch" between the NSEC-owner "_domainkey.davidkyburz.ch" and the NextOwner "autoconfig.davidkyburz.ch". So the zone confirmes the not-existence of that Wildcard-expansion.
Bitmap: NS, RRSIG, NSEC Validated: RRSIG-Owner _domainkey.davidkyburz.ch., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 29.07.2024, 00:17:28 +, Signature-Inception: 07.07.2024, 23:53:32 +, KeyTag 24647, Signer-Name: davidkyburz.ch
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| CAA-Query sends a valid NSEC RR as result with the query name "davidkyburz.ch" equal the NSEC-owner "davidkyburz.ch" and the NextOwner "_dmarc.davidkyburz.ch". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, RRSIG, NSEC, DNSKEY Validated: RRSIG-Owner davidkyburz.ch., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 30.07.2024, 04:26:50 +, Signature-Inception: 09.07.2024, 03:48:02 +, KeyTag 24647, Signer-Name: davidkyburz.ch
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
Zone: www.davidkyburz.ch
|
|
www.davidkyburz.ch
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone has a valid NSEC RR as result with the domain name between the NSEC-Owner "www.davidkyburz.ch" and the NextOwner "davidkyburz.ch". So the parent zone confirmes the non-existence of a DS RR.
Bitmap: A, RRSIG, NSEC
|
|
|
|
|
| RRSIG Type 1 validates the A - Result: 172.245.88.197
Validated: RRSIG-Owner www.davidkyburz.ch., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 26.07.2024, 13:57:25 +, Signature-Inception: 05.07.2024, 13:45:07 +, KeyTag 24647, Signer-Name: davidkyburz.ch
|
|
|
|
|
| CNAME-Query sends a valid NSEC RR as result with the query name "www.davidkyburz.ch" equal the NSEC-owner "www.davidkyburz.ch" and the NextOwner "davidkyburz.ch". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, RRSIG, NSEC Validated: RRSIG-Owner www.davidkyburz.ch., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 27.07.2024, 20:43:42 +, Signature-Inception: 06.07.2024, 20:24:49 +, KeyTag 24647, Signer-Name: davidkyburz.ch
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TXT-Query sends a valid NSEC RR as result with the query name "www.davidkyburz.ch" equal the NSEC-owner "www.davidkyburz.ch" and the NextOwner "davidkyburz.ch". So the zone confirmes the not-existence of that TXT RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, RRSIG, NSEC Validated: RRSIG-Owner www.davidkyburz.ch., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 27.07.2024, 20:43:42 +, Signature-Inception: 06.07.2024, 20:24:49 +, KeyTag 24647, Signer-Name: davidkyburz.ch
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| AAAA-Query sends a valid NSEC RR as result with the query name "www.davidkyburz.ch" equal the NSEC-owner "www.davidkyburz.ch" and the NextOwner "davidkyburz.ch". So the zone confirmes the not-existence of that AAAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, RRSIG, NSEC Validated: RRSIG-Owner www.davidkyburz.ch., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 27.07.2024, 20:43:42 +, Signature-Inception: 06.07.2024, 20:24:49 +, KeyTag 24647, Signer-Name: davidkyburz.ch
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TLSA-Query (_443._tcp.www.davidkyburz.ch) sends a valid NSEC RR as result with the owner name www.davidkyburz.ch. So that's the Closest Encloser of the query name. TLSA-Query sends a valid NSEC RR as result and covers the Wildcard expansion of the ClosestEncloser with the owner "www.davidkyburz.ch" and the NextOwner "davidkyburz.ch". So that NSEC confirms the not-existence of the Wildcard expansion. TLSA-Query (_443._tcp.www.davidkyburz.ch) sends a valid NSEC RR as result with the query name "_443._tcp.www.davidkyburz.ch" between the NSEC-owner "www.davidkyburz.ch" and the NextOwner "davidkyburz.ch". So the zone confirmes the not-existence of that TLSA RR.TLSA-Query (_443._tcp.www.davidkyburz.ch) sends a valid NSEC RR as result with the parent Wildcard "*._tcp.www.davidkyburz.ch" between the NSEC-owner "www.davidkyburz.ch" and the NextOwner "davidkyburz.ch". So the zone confirmes the not-existence of that Wildcard-expansion.
Bitmap: A, RRSIG, NSEC Validated: RRSIG-Owner www.davidkyburz.ch., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 27.07.2024, 20:43:42 +, Signature-Inception: 06.07.2024, 20:24:49 +, KeyTag 24647, Signer-Name: davidkyburz.ch
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| CAA-Query sends a valid NSEC RR as result with the query name "www.davidkyburz.ch" equal the NSEC-owner "www.davidkyburz.ch" and the NextOwner "davidkyburz.ch". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, RRSIG, NSEC Validated: RRSIG-Owner www.davidkyburz.ch., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 27.07.2024, 20:43:42 +, Signature-Inception: 06.07.2024, 20:24:49 +, KeyTag 24647, Signer-Name: davidkyburz.ch
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|