| Zone (*) | DNSSEC - Informations |
|---|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 14631, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 21.06.2021, 00:00:00 +, Signature-Inception: 31.05.2021, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: de
|
|
de
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 26755, DigestType 2 and Digest 80E1eAmllUMRzLgq3hFMbB1ySnXAOVE3qjl4A1Ql540=
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner de., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 21.06.2021, 21:00:00 +, Signature-Inception: 08.06.2021, 20:00:00 +, KeyTag 14631, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 14631 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 26755, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 26895, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner de., Algorithm: 8, 1 Labels, original TTL: 300 sec, Signature-expiration: 21.06.2021, 11:44:32 +, Signature-Inception: 07.06.2021, 10:14:32 +, KeyTag 26755, Signer-Name: de
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 26755 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 26755, DigestType 2 and Digest "80E1eAmllUMRzLgq3hFMbB1ySnXAOVE3qjl4A1Ql540=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: georg-ledermann.de
|
|
georg-ledermann.de
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 13, KeyTag 15090, DigestType 2 and Digest 0OQLw39mPVowIJyRlActrWr8zB1UvrOurtbt5mj4ML0=
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner georg-ledermann.de., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 20.06.2021, 04:04:03 +, Signature-Inception: 06.06.2021, 02:34:03 +, KeyTag 26895, Signer-Name: de
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 26895 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 1 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 13, KeyTag 15090, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner georg-ledermann.de., Algorithm: 13, 2 Labels, original TTL: 10800 sec, Signature-expiration: 17.06.2021, 00:00:00 +, Signature-Inception: 27.05.2021, 00:00:00 +, KeyTag 15090, Signer-Name: georg-ledermann.de
|
|
|
|
|
| • Status: Good - Algorithmus 13 and DNSKEY with KeyTag 15090 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 15090, DigestType 2 and Digest "0OQLw39mPVowIJyRlActrWr8zB1UvrOurtbt5mj4ML0=" validates local Key with the same values
|
|
|
|
|
| RRSIG Type 1 validates the A - Result: 116.203.125.190
Validated: RRSIG-Owner georg-ledermann.de., Algorithm: 13, 2 Labels, original TTL: 10800 sec, Signature-expiration: 17.06.2021, 00:00:00 +, Signature-Inception: 27.05.2021, 00:00:00 +, KeyTag 15090, Signer-Name: georg-ledermann.de
|
|
|
|
|
| RRSIG Type 16 validates the TXT - Result: v=spf1 include:_mailcust.gandi.net ?all
google-site-verification:ksBwNmt147MLD0QnYX3ZAfpNJ-fn_NR079vr55viZNk
Validated: RRSIG-Owner georg-ledermann.de., Algorithm: 13, 2 Labels, original TTL: 1800 sec, Signature-expiration: 17.06.2021, 00:00:00 +, Signature-Inception: 27.05.2021, 00:00:00 +, KeyTag 15090, Signer-Name: georg-ledermann.de
|
|
|
|
|
| RRSIG Type 28 validates the AAAA - Result: 2A01:04F8:0C2C:2088:0000:0000:0000:0001
Validated: RRSIG-Owner georg-ledermann.de., Algorithm: 13, 2 Labels, original TTL: 1800 sec, Signature-expiration: 17.06.2021, 00:00:00 +, Signature-Inception: 27.05.2021, 00:00:00 +, KeyTag 15090, Signer-Name: georg-ledermann.de
|
|
|
|
|
| CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "p49fr6adrhbm4bgig43v3rtmo87rrek1" equal the hashed NSEC3-owner "p49fr6adrhbm4bgig43v3rtmo87rrek1" and the hashed NextOwner "p49fr6adrhbm4bgig43v3rtmo87rrek2". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, DNSKEY, NSEC3PARAM, CDS Validated: RRSIG-Owner p49fr6adrhbm4bgig43v3rtmo87rrek1.georg-ledermann.de., Algorithm: 13, 3 Labels, original TTL: 10800 sec, Signature-expiration: 17.06.2021, 00:00:00 +, Signature-Inception: 27.05.2021, 00:00:00 +, KeyTag 15090, Signer-Name: georg-ledermann.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TLSA-Query (_443._tcp.georg-ledermann.de) sends a valid NSEC3 RR as result with the hashed owner name "6jk6ireef4lucshvjgadg917a0ms9nam" (unhashed: _tcp.georg-ledermann.de). So that's the Closest Encloser of the query name.
Bitmap: No Bitmap? Validated: RRSIG-Owner 6jk6ireef4lucshvjgadg917a0ms9nam.georg-ledermann.de., Algorithm: 13, 3 Labels, original TTL: 10800 sec, Signature-expiration: 17.06.2021, 00:00:00 +, Signature-Inception: 27.05.2021, 00:00:00 +, KeyTag 15090, Signer-Name: georg-ledermann.de
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Wildcard expansion of the ClosestEncloser "jdbgfp2cde6m17ck7b6jtd86hi1gd9lf" (unhashed: *._tcp.georg-ledermann.de) with the owner "jdbgfp2cde6m17ck7b6jtd86hi1gd9le" and the NextOwner "jdbgfp2cde6m17ck7b6jtd86hi1gd9lg". So that NSEC3 confirms the not-existence of the Wildcard expansion.
Bitmap: No Bitmap? Validated: RRSIG-Owner jdbgfp2cde6m17ck7b6jtd86hi1gd9le.georg-ledermann.de., Algorithm: 13, 3 Labels, original TTL: 10800 sec, Signature-expiration: 17.06.2021, 00:00:00 +, Signature-Inception: 27.05.2021, 00:00:00 +, KeyTag 15090, Signer-Name: georg-ledermann.de
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| TLSA-Query (_443._tcp.georg-ledermann.de) sends a valid NSEC3 RR as result with the hashed query name "p7uho2l9ljfl8l9qg2ocptr6ts5qd593" between the hashed NSEC3-owner "p7uho2l9ljfl8l9qg2ocptr6ts5qd592" and the hashed NextOwner "p7uho2l9ljfl8l9qg2ocptr6ts5qd594". So the zone confirmes the not-existence of that TLSA RR.
Bitmap: No Bitmap? Validated: RRSIG-Owner p7uho2l9ljfl8l9qg2ocptr6ts5qd592.georg-ledermann.de., Algorithm: 13, 3 Labels, original TTL: 10800 sec, Signature-expiration: 17.06.2021, 00:00:00 +, Signature-Inception: 27.05.2021, 00:00:00 +, KeyTag 15090, Signer-Name: georg-ledermann.de
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| CAA-Query sends a valid NSEC3 RR as result with the hashed query name "p49fr6adrhbm4bgig43v3rtmo87rrek1" equal the hashed NSEC3-owner "p49fr6adrhbm4bgig43v3rtmo87rrek1" and the hashed NextOwner "p49fr6adrhbm4bgig43v3rtmo87rrek2". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, AAAA, RRSIG, DNSKEY, NSEC3PARAM, CDS Validated: RRSIG-Owner p49fr6adrhbm4bgig43v3rtmo87rrek1.georg-ledermann.de., Algorithm: 13, 3 Labels, original TTL: 10800 sec, Signature-expiration: 17.06.2021, 00:00:00 +, Signature-Inception: 27.05.2021, 00:00:00 +, KeyTag 15090, Signer-Name: georg-ledermann.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
Zone: www.georg-ledermann.de
|
|
www.georg-ledermann.de
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "msgr4c63kt3s2hlpnuk05m5klq4pt2lc" between the hashed NSEC3-owner "msgr4c63kt3s2hlpnuk05m5klq4pt2lc" and the hashed NextOwner "msgr4c63kt3s2hlpnuk05m5klq4pt2ld". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner msgr4c63kt3s2hlpnuk05m5klq4pt2lc.georg-ledermann.de., Algorithm: 13, 3 Labels, original TTL: 10800 sec, Signature-expiration: 17.06.2021, 00:00:00 +, Signature-Inception: 27.05.2021, 00:00:00 +, KeyTag 15090, Signer-Name: georg-ledermann.de
|
|
|
|
|
| RRSIG Type 1 validates the A - Result: 116.203.125.190
Validated: RRSIG-Owner www.georg-ledermann.de., Algorithm: 13, 3 Labels, original TTL: 1800 sec, Signature-expiration: 17.06.2021, 00:00:00 +, Signature-Inception: 27.05.2021, 00:00:00 +, KeyTag 15090, Signer-Name: georg-ledermann.de
|
|
|
|
|
| RRSIG Type 28 validates the AAAA - Result: 2A01:04F8:0C2C:2088:0000:0000:0000:0001
Validated: RRSIG-Owner www.georg-ledermann.de., Algorithm: 13, 3 Labels, original TTL: 1800 sec, Signature-expiration: 17.06.2021, 00:00:00 +, Signature-Inception: 27.05.2021, 00:00:00 +, KeyTag 15090, Signer-Name: georg-ledermann.de
|
|
|
|
|
| CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "msgr4c63kt3s2hlpnuk05m5klq4pt2lc" equal the hashed NSEC3-owner "msgr4c63kt3s2hlpnuk05m5klq4pt2lc" and the hashed NextOwner "msgr4c63kt3s2hlpnuk05m5klq4pt2ld". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner msgr4c63kt3s2hlpnuk05m5klq4pt2lc.georg-ledermann.de., Algorithm: 13, 3 Labels, original TTL: 10800 sec, Signature-expiration: 17.06.2021, 00:00:00 +, Signature-Inception: 27.05.2021, 00:00:00 +, KeyTag 15090, Signer-Name: georg-ledermann.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TXT-Query sends a valid NSEC3 RR as result with the hashed query name "msgr4c63kt3s2hlpnuk05m5klq4pt2lc" equal the hashed NSEC3-owner "msgr4c63kt3s2hlpnuk05m5klq4pt2lc" and the hashed NextOwner "msgr4c63kt3s2hlpnuk05m5klq4pt2ld". So the zone confirmes the not-existence of that TXT RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner msgr4c63kt3s2hlpnuk05m5klq4pt2lc.georg-ledermann.de., Algorithm: 13, 3 Labels, original TTL: 10800 sec, Signature-expiration: 17.06.2021, 00:00:00 +, Signature-Inception: 27.05.2021, 00:00:00 +, KeyTag 15090, Signer-Name: georg-ledermann.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TLSA-Query (_443._tcp.www.georg-ledermann.de) sends a valid NSEC3 RR as result with the hashed owner name "msgr4c63kt3s2hlpnuk05m5klq4pt2lc" (unhashed: www.georg-ledermann.de). So that's the Closest Encloser of the query name.
Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner msgr4c63kt3s2hlpnuk05m5klq4pt2lc.georg-ledermann.de., Algorithm: 13, 3 Labels, original TTL: 10800 sec, Signature-expiration: 17.06.2021, 00:00:00 +, Signature-Inception: 27.05.2021, 00:00:00 +, KeyTag 15090, Signer-Name: georg-ledermann.de
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Next Closer Name "gve4f8tv5f0653tqackkatin5ha5j2j2" (unhashed: _tcp.www.georg-ledermann.de) with the owner "gve4f8tv5f0653tqackkatin5ha5j2j1" and the NextOwner "gve4f8tv5f0653tqackkatin5ha5j2j3". So that NSEC3 confirms the not-existence of the Next Closer Name.
Bitmap: No Bitmap? Validated: RRSIG-Owner gve4f8tv5f0653tqackkatin5ha5j2j1.georg-ledermann.de., Algorithm: 13, 3 Labels, original TTL: 10800 sec, Signature-expiration: 17.06.2021, 00:00:00 +, Signature-Inception: 27.05.2021, 00:00:00 +, KeyTag 15090, Signer-Name: georg-ledermann.de
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Wildcard expansion of the ClosestEncloser "oo5bmlu5e275biunknjjpvtrshklh5k4" (unhashed: *.www.georg-ledermann.de) with the owner "oo5bmlu5e275biunknjjpvtrshklh5k3" and the NextOwner "oo5bmlu5e275biunknjjpvtrshklh5k5". So that NSEC3 confirms the not-existence of the Wildcard expansion.
Bitmap: No Bitmap? Validated: RRSIG-Owner oo5bmlu5e275biunknjjpvtrshklh5k3.georg-ledermann.de., Algorithm: 13, 3 Labels, original TTL: 10800 sec, Signature-expiration: 17.06.2021, 00:00:00 +, Signature-Inception: 27.05.2021, 00:00:00 +, KeyTag 15090, Signer-Name: georg-ledermann.de
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| CAA-Query sends a valid NSEC3 RR as result with the hashed query name "msgr4c63kt3s2hlpnuk05m5klq4pt2lc" equal the hashed NSEC3-owner "msgr4c63kt3s2hlpnuk05m5klq4pt2lc" and the hashed NextOwner "msgr4c63kt3s2hlpnuk05m5klq4pt2ld". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner msgr4c63kt3s2hlpnuk05m5klq4pt2lc.georg-ledermann.de., Algorithm: 13, 3 Labels, original TTL: 10800 sec, Signature-expiration: 17.06.2021, 00:00:00 +, Signature-Inception: 27.05.2021, 00:00:00 +, KeyTag 15090, Signer-Name: georg-ledermann.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|