| Zone (*) | DNSSEC - Informations |
|---|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 11019, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 11.08.2023, 00:00:00 +, Signature-Inception: 21.07.2023, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: de
|
|
de
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 26755, DigestType 2 and Digest 80E1eAmllUMRzLgq3hFMbB1ySnXAOVE3qjl4A1Ql540=
|
|
|
|
|
| 2 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner de., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 07.08.2023, 05:00:00 +, Signature-Inception: 25.07.2023, 04:00:00 +, KeyTag 11019, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 11019 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 24951, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 26755, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner de., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 05.08.2023, 22:41:45 +, Signature-Inception: 22.07.2023, 21:11:45 +, KeyTag 26755, Signer-Name: de
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 26755 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 26755, DigestType 2 and Digest "80E1eAmllUMRzLgq3hFMbB1ySnXAOVE3qjl4A1Ql540=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: bayern.de
|
|
bayern.de
| 2 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 42094, DigestType 2 and Digest BwYc1psx/yv59Ft8PUNrSw5gJnQpTwgULSQZ42y9JLU=
|
|
|
|
|
| DS with Algorithm 8, KeyTag 30489, DigestType 2 and Digest +dRF1U5Lc+PGyyJNcEa8LoDZFxne9M9NypyRzUoyldo=
|
|
|
|
|
| 2 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner bayern.de., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 07.08.2023, 06:30:58 +, Signature-Inception: 24.07.2023, 05:00:58 +, KeyTag 24951, Signer-Name: de
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 24951 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 42094, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 42768, Flags 256
|
|
|
|
|
| 2 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner bayern.de., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 05.08.2023, 08:38:49 +, Signature-Inception: 22.07.2023, 08:16:56 +, KeyTag 42094, Signer-Name: bayern.de
|
|
|
|
|
| RRSIG-Owner bayern.de., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 05.08.2023, 08:38:49 +, Signature-Inception: 22.07.2023, 08:16:56 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 42094 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 42768 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 42094, DigestType 2 and Digest "BwYc1psx/yv59Ft8PUNrSw5gJnQpTwgULSQZ42y9JLU=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: finanzamt.bayern.de
|
|
finanzamt.bayern.de
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "7c0scj1hi2e3n5l6ch0qtblmfepfl5ar" between the hashed NSEC3-owner "7c0scj1hi2e3n5l6ch0qtblmfepfl5ar" and the hashed NextOwner "7c39hsvnvedvb96ti31obmurmig23phr". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: MX, TXT, RRSIG, CAA Validated: RRSIG-Owner 7c0scj1hi2e3n5l6ch0qtblmfepfl5ar.bayern.de., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 31.07.2023, 00:55:09 +, Signature-Inception: 17.07.2023, 00:34:30 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
|
|
| 0 DNSKEY RR found
|
|
|
|
|
|
|
|
|
|
|
| RRSIG Type 16 validates the TXT - Result: v=spf1 include:bayern.de -all
Validated: RRSIG-Owner finanzamt.bayern.de., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 04.08.2023, 01:59:31 +, Signature-Inception: 21.07.2023, 01:48:07 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
|
|
| RRSIG Type 257 validates the CAA - Result: 5|issuedtrust.de
9|issuewilddtrust.de
12|contactemailhostmaster@elster.de
Validated: RRSIG-Owner finanzamt.bayern.de., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 31.07.2023, 00:55:09 +, Signature-Inception: 17.07.2023, 00:34:30 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
|
|
| A-Query sends a valid NSEC3 RR as result with the hashed query name "7c0scj1hi2e3n5l6ch0qtblmfepfl5ar" equal the hashed NSEC3-owner "7c0scj1hi2e3n5l6ch0qtblmfepfl5ar" and the hashed NextOwner "7c39hsvnvedvb96ti31obmurmig23phr". So the zone confirmes the not-existence of that A RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: MX, TXT, RRSIG, CAA Validated: RRSIG-Owner 7c0scj1hi2e3n5l6ch0qtblmfepfl5ar.bayern.de., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 31.07.2023, 00:55:09 +, Signature-Inception: 17.07.2023, 00:34:30 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "7c0scj1hi2e3n5l6ch0qtblmfepfl5ar" equal the hashed NSEC3-owner "7c0scj1hi2e3n5l6ch0qtblmfepfl5ar" and the hashed NextOwner "7c39hsvnvedvb96ti31obmurmig23phr". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: MX, TXT, RRSIG, CAA Validated: RRSIG-Owner 7c0scj1hi2e3n5l6ch0qtblmfepfl5ar.bayern.de., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 31.07.2023, 00:55:09 +, Signature-Inception: 17.07.2023, 00:34:30 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| AAAA-Query sends a valid NSEC3 RR as result with the hashed query name "7c0scj1hi2e3n5l6ch0qtblmfepfl5ar" equal the hashed NSEC3-owner "7c0scj1hi2e3n5l6ch0qtblmfepfl5ar" and the hashed NextOwner "7c39hsvnvedvb96ti31obmurmig23phr". So the zone confirmes the not-existence of that AAAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: MX, TXT, RRSIG, CAA Validated: RRSIG-Owner 7c0scj1hi2e3n5l6ch0qtblmfepfl5ar.bayern.de., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 31.07.2023, 00:55:09 +, Signature-Inception: 17.07.2023, 00:34:30 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TLSA-Query (_443._tcp.finanzamt.bayern.de) sends a valid NSEC3 RR as result with the hashed owner name "7c0scj1hi2e3n5l6ch0qtblmfepfl5ar" (unhashed: finanzamt.bayern.de). So that's the Closest Encloser of the query name.
Bitmap: MX, TXT, RRSIG, CAA Validated: RRSIG-Owner 7c0scj1hi2e3n5l6ch0qtblmfepfl5ar.bayern.de., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 31.07.2023, 00:55:09 +, Signature-Inception: 17.07.2023, 00:34:30 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Next Closer Name "g1gt5tupdk0cj0cbtogbi5gvec8lf6nb" (unhashed: _tcp.finanzamt.bayern.de) with the owner "g1ejmv79qt0uol6q91t0rjjirrfn4ems" and the NextOwner "g1hii25fdjg8eqa7lr17hr50kl5447g9". So that NSEC3 confirms the not-existence of the Next Closer Name.
Bitmap: CNAME, RRSIG Validated: RRSIG-Owner g1ejmv79qt0uol6q91t0rjjirrfn4ems.bayern.de., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 03.08.2023, 18:46:14 +, Signature-Inception: 20.07.2023, 18:10:26 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Wildcard expansion of the ClosestEncloser "1jl3t8qh4d9k4se4176717gi33osapda" (unhashed: *.finanzamt.bayern.de) with the owner "1jkvd5ml2t5cgejpdcnv51heb6v1sjk6" and the NextOwner "1jnb3qhr4aoohuoedq8tr02984ni5bl7". So that NSEC3 confirms the not-existence of the Wildcard expansion.
Bitmap: CNAME, RRSIG Validated: RRSIG-Owner 1jkvd5ml2t5cgejpdcnv51heb6v1sjk6.bayern.de., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 30.07.2023, 01:45:23 +, Signature-Inception: 16.07.2023, 01:06:58 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
Zone: www.finanzamt.bayern.de
|
|
www.finanzamt.bayern.de
| 0 DS RR in the parent zone found
|
|
|
|
|
| RRSIG Type 5 validates the CNAME - Result: rvr-prx.bayern.de
Validated: RRSIG-Owner www.finanzamt.bayern.de., Algorithm: 8, 4 Labels, original TTL: 3600 sec, Signature-expiration: 01.08.2023, 12:45:42 +, Signature-Inception: 18.07.2023, 12:37:09 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 11019, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 11.08.2023, 00:00:00 +, Signature-Inception: 21.07.2023, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: de
|
|
de
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 26755, DigestType 2 and Digest 80E1eAmllUMRzLgq3hFMbB1ySnXAOVE3qjl4A1Ql540=
|
|
|
|
|
| 2 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner de., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 07.08.2023, 05:00:00 +, Signature-Inception: 25.07.2023, 04:00:00 +, KeyTag 11019, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 11019 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 24951, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 26755, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner de., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 05.08.2023, 22:41:45 +, Signature-Inception: 22.07.2023, 21:11:45 +, KeyTag 26755, Signer-Name: de
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 26755 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 26755, DigestType 2 and Digest "80E1eAmllUMRzLgq3hFMbB1ySnXAOVE3qjl4A1Ql540=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: bayern.de
|
|
bayern.de
| 2 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 42094, DigestType 2 and Digest BwYc1psx/yv59Ft8PUNrSw5gJnQpTwgULSQZ42y9JLU=
|
|
|
|
|
| DS with Algorithm 8, KeyTag 30489, DigestType 2 and Digest +dRF1U5Lc+PGyyJNcEa8LoDZFxne9M9NypyRzUoyldo=
|
|
|
|
|
| 2 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner bayern.de., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 07.08.2023, 06:30:58 +, Signature-Inception: 24.07.2023, 05:00:58 +, KeyTag 24951, Signer-Name: de
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 24951 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 42094, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 42768, Flags 256
|
|
|
|
|
| 2 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner bayern.de., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 05.08.2023, 08:38:49 +, Signature-Inception: 22.07.2023, 08:16:56 +, KeyTag 42094, Signer-Name: bayern.de
|
|
|
|
|
| RRSIG-Owner bayern.de., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 05.08.2023, 08:38:49 +, Signature-Inception: 22.07.2023, 08:16:56 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 42094 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 42768 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 42094, DigestType 2 and Digest "BwYc1psx/yv59Ft8PUNrSw5gJnQpTwgULSQZ42y9JLU=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: rvr-prx.bayern.de
|
|
rvr-prx.bayern.de
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "7hrlubn8r37g1p5jksqaq9usjrlcjckt" between the hashed NSEC3-owner "7hrlubn8r37g1p5jksqaq9usjrlcjckt" and the hashed NextOwner "7hspe3rq2ppc0lohg02cjhderv0q83ta". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: A, RRSIG Validated: RRSIG-Owner 7hrlubn8r37g1p5jksqaq9usjrlcjckt.bayern.de., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 02.08.2023, 00:13:28 +, Signature-Inception: 19.07.2023, 00:12:31 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
|
|
| 0 DNSKEY RR found
|
|
|
|
|
|
|
|
|
|
|
| RRSIG Type 1 validates the A - Result: 195.200.71.141
Validated: RRSIG-Owner rvr-prx.bayern.de., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 04.08.2023, 03:20:49 +, Signature-Inception: 21.07.2023, 02:59:41 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
|
|
| RRSIG Type 52 validates the TLSA - Result (_443._tcp.rvr-prx.bayern.de): _443._tcp.rvr-prx.bayern.de: CertUsage 0 (PKIX-TA, CA constraint), Selector: 0 (Cert, Full certificate), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 67add1166b020ae61b8f5fc96813c04c2aa589960796865572a3c7e737613dfd
Validated: RRSIG-Owner _443._tcp.rvr-prx.bayern.de., Algorithm: 8, 5 Labels, original TTL: 3600 sec, Signature-expiration: 31.07.2023, 21:49:15 +, Signature-Inception: 17.07.2023, 21:34:13 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
|
|
| CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "7hrlubn8r37g1p5jksqaq9usjrlcjckt" equal the hashed NSEC3-owner "7hrlubn8r37g1p5jksqaq9usjrlcjckt" and the hashed NextOwner "7hspe3rq2ppc0lohg02cjhderv0q83ta". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, RRSIG Validated: RRSIG-Owner 7hrlubn8r37g1p5jksqaq9usjrlcjckt.bayern.de., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 02.08.2023, 00:13:28 +, Signature-Inception: 19.07.2023, 00:12:31 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TXT-Query sends a valid NSEC3 RR as result with the hashed query name "7hrlubn8r37g1p5jksqaq9usjrlcjckt" equal the hashed NSEC3-owner "7hrlubn8r37g1p5jksqaq9usjrlcjckt" and the hashed NextOwner "7hspe3rq2ppc0lohg02cjhderv0q83ta". So the zone confirmes the not-existence of that TXT RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, RRSIG Validated: RRSIG-Owner 7hrlubn8r37g1p5jksqaq9usjrlcjckt.bayern.de., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 02.08.2023, 00:13:28 +, Signature-Inception: 19.07.2023, 00:12:31 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| AAAA-Query sends a valid NSEC3 RR as result with the hashed query name "7hrlubn8r37g1p5jksqaq9usjrlcjckt" equal the hashed NSEC3-owner "7hrlubn8r37g1p5jksqaq9usjrlcjckt" and the hashed NextOwner "7hspe3rq2ppc0lohg02cjhderv0q83ta". So the zone confirmes the not-existence of that AAAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, RRSIG Validated: RRSIG-Owner 7hrlubn8r37g1p5jksqaq9usjrlcjckt.bayern.de., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 02.08.2023, 00:13:28 +, Signature-Inception: 19.07.2023, 00:12:31 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| CAA-Query sends a valid NSEC3 RR as result with the hashed query name "7hrlubn8r37g1p5jksqaq9usjrlcjckt" equal the hashed NSEC3-owner "7hrlubn8r37g1p5jksqaq9usjrlcjckt" and the hashed NextOwner "7hspe3rq2ppc0lohg02cjhderv0q83ta". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, RRSIG Validated: RRSIG-Owner 7hrlubn8r37g1p5jksqaq9usjrlcjckt.bayern.de., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 02.08.2023, 00:13:28 +, Signature-Inception: 19.07.2023, 00:12:31 +, KeyTag 42768, Signer-Name: bayern.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|