Zone (*) | DNSSEC - Informations |
---|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 4 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 38696, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 46441, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 53148, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 22.07.2025, 00:00:00 +, Signature-Inception: 01.07.2025, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: au
|
|
au
| 2 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 51895, DigestType 2 and Digest bH1Qm9TfMq8lX/hHFSt7ADFqwLpEuFOzyfnHEZqqWZw=
|
|
|
|
|
| DS with Algorithm 8, KeyTag 1775, DigestType 2 and Digest ZN/d3SxoqlzGfljNiPH714BPkRqj0zFMtZU5djoK+J8=
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner au., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 17.07.2025, 05:00:00 +, Signature-Inception: 04.07.2025, 04:00:00 +, KeyTag 46441, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 46441 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 1775, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 63364, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner au., Algorithm: 8, 1 Labels, original TTL: 43200 sec, Signature-expiration: 31.07.2025, 22:57:23 +, Signature-Inception: 19.06.2025, 21:27:23 +, KeyTag 1775, Signer-Name: au
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 1775 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 1775, DigestType 2 and Digest "ZN/d3SxoqlzGfljNiPH714BPkRqj0zFMtZU5djoK+J8=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: com.au
|
|
com.au
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 14185, DigestType 2 and Digest k5S+oJ9evZE4SqXNA5ems5X9KymceRKXkkPNaJujh9s=
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner com.au., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 27.07.2025, 00:00:33 +, Signature-Inception: 14.06.2025, 22:30:33 +, KeyTag 63364, Signer-Name: au
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 63364 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 3 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 7683, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 14185, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 58863, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner com.au., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 22.07.2025, 15:17:37 +, Signature-Inception: 01.07.2025, 14:17:37 +, KeyTag 14185, Signer-Name: com.au
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 14185 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 14185, DigestType 2 and Digest "k5S+oJ9evZE4SqXNA5ems5X9KymceRKXkkPNaJujh9s=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: ozlivery.com.au
|
|
ozlivery.com.au
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "kqk30nf8nehg7k9om48k5iup11rdnhri" between the hashed NSEC3-owner "kqjvdk8lmceg923nqdaqg7o2mgoue2ip" and the hashed NextOwner "kql9viq9lcaf8okpkgnm33k3t0q62hok". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: NS, DS, RRSIG Validated: RRSIG-Owner kqjvdk8lmceg923nqdaqg7o2mgoue2ip.com.au., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 22.07.2025, 15:17:37 +, Signature-Inception: 01.07.2025, 14:17:37 +, KeyTag 58863, Signer-Name: com.au
|
|
|
|
|
| DS-Query in the parent zone sends valid NSEC3 RR with the Hash "md9i9voubqb55nj87e5v632qbmvr5iou" as Owner. That's the Hash of "com.au" with the NextHashedOwnerName "mda0out18h69c95kq61al5q3216mu6me". So that domain name is the Closest Encloser of "ozlivery.com.au". Opt-Out: True.
Bitmap: NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner md9i9voubqb55nj87e5v632qbmvr5iou.com.au., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 25.07.2025, 15:15:35 +, Signature-Inception: 04.07.2025, 14:15:35 +, KeyTag 58863, Signer-Name: com.au
|
|
|
|
|
| 0 DNSKEY RR found
|
|
|
|
|
|
|
|
|
Zone: ha.ozlivery.com.au
|
|
ha.ozlivery.com.au
| 0 DS RR in the parent zone found
|
|
|
Zone: www.ha.ozlivery.com.au
|
|
www.ha.ozlivery.com.au
| 0 DS RR in the parent zone found
|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 4 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 38696, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 46441, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 53148, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 22.07.2025, 00:00:00 +, Signature-Inception: 01.07.2025, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: com
|
|
com
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 13, KeyTag 19718, DigestType 2 and Digest isuwzSj0ElCoCkkTiUJNNBUi2Uaw2gwCkfLT13HXgFo=
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 17.07.2025, 05:00:00 +, Signature-Inception: 04.07.2025, 04:00:00 +, KeyTag 46441, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 46441 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 13, KeyTag 19718, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 13, KeyTag 40097, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner com., Algorithm: 13, 1 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2025, 14:02:35 +, Signature-Inception: 01.07.2025, 13:57:35 +, KeyTag 19718, Signer-Name: com
|
|
|
|
|
| • Status: Good - Algorithmus 13 and DNSKEY with KeyTag 19718 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 19718, DigestType 2 and Digest "isuwzSj0ElCoCkkTiUJNNBUi2Uaw2gwCkfLT13HXgFo=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: cfargotunnel.com
|
|
cfargotunnel.com
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "8fd4bm0r5fm0mtku0pv7d34aqp9sm5t4" between the hashed NSEC3-owner "8fd4a4mpl0crfc61qt6o58gkah3vquhg" and the hashed NextOwner "8fd4ijtmhjaitkh8o2pm8odk6a7ce2c2". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: NS, DS, RRSIG Validated: RRSIG-Owner 8fd4a4mpl0crfc61qt6o58gkah3vquhg.com., Algorithm: 13, 2 Labels, original TTL: 900 sec, Signature-expiration: 08.07.2025, 01:22:45 +, Signature-Inception: 01.07.2025, 00:12:45 +, KeyTag 40097, Signer-Name: com
|
|
|
|
|
| DS-Query in the parent zone sends valid NSEC3 RR with the Hash "ck0pojmg874ljref7efn8430qvit8bsm" as Owner. That's the Hash of "com" with the NextHashedOwnerName "ck0q3udg8cekkae7rukpgct1dvssh8ll". So that domain name is the Closest Encloser of "cfargotunnel.com". Opt-Out: True.
Bitmap: NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner ck0pojmg874ljref7efn8430qvit8bsm.com., Algorithm: 13, 2 Labels, original TTL: 900 sec, Signature-expiration: 10.07.2025, 00:25:09 +, Signature-Inception: 02.07.2025, 23:15:09 +, KeyTag 40097, Signer-Name: com
|
|
|
|
|
| 0 DNSKEY RR found
|
|
|
|
|
|
|
|
|
Zone: 6f3cb747-4866-4e3c-aff6-652f2a77fda6.cfargotunnel.com
|
|
6f3cb747-4866-4e3c-aff6-652f2a77fda6.cfargotunnel.com
| 0 DS RR in the parent zone found
|
|
|
|
|
| 0 DNSKEY RR found
|
|
|
|
|
|
|