Zone (*) | DNSSEC - Informations |
---|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 3 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 5613, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20038, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 22.07.2024, 00:00:00 +, Signature-Inception: 01.07.2024, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: de
|
|
de
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 26755, DigestType 2 and Digest 80E1eAmllUMRzLgq3hFMbB1ySnXAOVE3qjl4A1Ql540=
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner de., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 22.07.2024, 20:00:00 +, Signature-Inception: 09.07.2024, 19:00:00 +, KeyTag 20038, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20038 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 26755, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 51483, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner de., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 18.07.2024, 21:52:03 +, Signature-Inception: 04.07.2024, 20:22:03 +, KeyTag 26755, Signer-Name: de
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 26755 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 26755, DigestType 2 and Digest "80E1eAmllUMRzLgq3hFMbB1ySnXAOVE3qjl4A1Ql540=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: kita-wexstrasse.de
|
|
kita-wexstrasse.de
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 22012, DigestType 2 and Digest mWtvFZ93SSO6hOR69h2qqDorqIje32UK0XBlR/jTPj8=
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner kita-wexstrasse.de., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 20.07.2024, 06:50:36 +, Signature-Inception: 06.07.2024, 05:20:36 +, KeyTag 51483, Signer-Name: de
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 51483 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 10513, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 22012, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 2 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner kita-wexstrasse.de., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| RRSIG-Owner kita-wexstrasse.de., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 22012, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 10513 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 22012 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 22012, DigestType 2 and Digest "mWtvFZ93SSO6hOR69h2qqDorqIje32UK0XBlR/jTPj8=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| RRSIG Type 1 validates the A - Result: 195.128.101.74
Validated: RRSIG-Owner kita-wexstrasse.de., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| RRSIG Type 1, expiration 2024-07-16 12:50:00 + doesn't validate the A - Result. Signature is invalid.
|
|
|
|
|
| CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "m6lp8gm0tc7tspq2ps9f30bc9iibrq9m" equal the hashed NSEC3-owner "m6lp8gm0tc7tspq2ps9f30bc9iibrq9m" and the hashed NextOwner "msdrhcdgjhlm60rcfv13o8o10902fg28". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner m6lp8gm0tc7tspq2ps9f30bc9iibrq9m.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TXT-Query sends a valid NSEC3 RR as result with the hashed query name "m6lp8gm0tc7tspq2ps9f30bc9iibrq9m" equal the hashed NSEC3-owner "m6lp8gm0tc7tspq2ps9f30bc9iibrq9m" and the hashed NextOwner "msdrhcdgjhlm60rcfv13o8o10902fg28". So the zone confirmes the not-existence of that TXT RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner m6lp8gm0tc7tspq2ps9f30bc9iibrq9m.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| AAAA-Query sends a valid NSEC3 RR as result with the hashed query name "m6lp8gm0tc7tspq2ps9f30bc9iibrq9m" equal the hashed NSEC3-owner "m6lp8gm0tc7tspq2ps9f30bc9iibrq9m" and the hashed NextOwner "msdrhcdgjhlm60rcfv13o8o10902fg28". So the zone confirmes the not-existence of that AAAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner m6lp8gm0tc7tspq2ps9f30bc9iibrq9m.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TLSA-Query (_443._tcp.kita-wexstrasse.de) sends a valid NSEC3 RR as result with the hashed owner name "m6lp8gm0tc7tspq2ps9f30bc9iibrq9m" (unhashed: kita-wexstrasse.de). So that's the Closest Encloser of the query name.
Bitmap: A, NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner m6lp8gm0tc7tspq2ps9f30bc9iibrq9m.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Next Closer Name "c6c92ajdpd1rdat6caafg1cvm9ur46na" (unhashed: _tcp.kita-wexstrasse.de) with the owner "9ur58qrl7kaeq7sqesffm0h7rlunp263" and the NextOwner "kb7u851mj35j2bi7i5m2db6pvn6b9unj". So that NSEC3 confirms the not-existence of the Next Closer Name.
Bitmap: A, RRSIG Validated: RRSIG-Owner 9ur58qrl7kaeq7sqesffm0h7rlunp263.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TLSA-Query sends a valid NSEC3 RR as result with the hashed owner name "msdrhcdgjhlm60rcfv13o8o10902fg28" (unhashed: *.kita-wexstrasse.de) as the Wildcard-Expansion of the Closest Encloser of the query name "935pmsuam9sqsskna767jf61e1ka4q1f". So the Wildcard-Expansion of the Closest Encloser confirms that the query name is generated via wildcard expansion (NoError instead of NXDomain).
Bitmap: A, RRSIG Validated: RRSIG-Owner msdrhcdgjhlm60rcfv13o8o10902fg28.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| CAA-Query sends a valid NSEC3 RR as result with the hashed query name "m6lp8gm0tc7tspq2ps9f30bc9iibrq9m" equal the hashed NSEC3-owner "m6lp8gm0tc7tspq2ps9f30bc9iibrq9m" and the hashed NextOwner "msdrhcdgjhlm60rcfv13o8o10902fg28". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner m6lp8gm0tc7tspq2ps9f30bc9iibrq9m.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
Zone: www.kita-wexstrasse.de
|
|
www.kita-wexstrasse.de
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone sends valid NSEC3 RR with the Hash "m6lp8gm0tc7tspq2ps9f30bc9iibrq9m" as Owner. That's the Hash of "kita-wexstrasse.de" with the NextHashedOwnerName "msdrhcdgjhlm60rcfv13o8o10902fg28". So that domain name is the Closest Encloser of "www.kita-wexstrasse.de". Opt-Out: False.
Bitmap: A, NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner m6lp8gm0tc7tspq2ps9f30bc9iibrq9m.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| The ClosestEncloser says, that "*.kita-wexstrasse.de" with the Hash "msdrhcdgjhlm60rcfv13o8o10902fg28" is a possible Wildcard of the DS Query Name. But the DS-Query in the parent zone sends a valid NSEC3 RR With the owner "m6lp8gm0tc7tspq2ps9f30bc9iibrq9m" and the Next Owner "msdrhcdgjhlm60rcfv13o8o10902fg28", so the Hash of the wildcard is between these hashes. So that NSEC3 proves the Not-existence of that wildcard expansion. Opt-Out: False.
Bitmap: A, NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner m6lp8gm0tc7tspq2ps9f30bc9iibrq9m.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| The ClosestEncloser says, that "*.kita-wexstrasse.de" with the Hash "msdrhcdgjhlm60rcfv13o8o10902fg28" is a possible Wildcard of the DS Query Name. But the DS-Query in the parent zone sends a valid NSEC3 RR With the owner "msdrhcdgjhlm60rcfv13o8o10902fg28" and the Next Owner "r117f23lhdvvg02ut2k88m2s78kcj7bs", so the Hash of the wildcard is between these hashes. So that NSEC3 proves the Not-existence of that wildcard expansion. Opt-Out: False.
Bitmap: A, RRSIG Validated: RRSIG-Owner msdrhcdgjhlm60rcfv13o8o10902fg28.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| RRSIG Type 1 validates the A - Result: 195.128.101.74. RRSIG Owner has 3 labels, RRSIG Labels = 2, so it's a wildcard expansion, the Query Name doesn't exists. An additional NSEC/NSEC3 is required to confirm the Not-Existence of the query name.
Validated: RRSIG-Owner www.kita-wexstrasse.de., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| A-Query sends a valid NSEC3 RR as result with the owner name "r117f23lhdvvg02ut2k88m2s78kcj7bs" greater the NextOwner-Name "2100cslnrdbd4smi643opp629br558bh", so the NSEC3 covers the end of the zone. The hashed query name "vr2786lvusu4bsdv2r8ol3gpbeso2pml" comes after the hashed Owner, so the zone confirmes the not-existence of that A RR.
Bitmap: No Bitmap? Validated: RRSIG-Owner r117f23lhdvvg02ut2k88m2s78kcj7bs.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| CNAME-Query sends a valid NSEC3 RR as result with the hashed owner name "m6lp8gm0tc7tspq2ps9f30bc9iibrq9m" (unhashed: kita-wexstrasse.de). So that's the Closest Encloser of the query name.
Bitmap: A, NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner m6lp8gm0tc7tspq2ps9f30bc9iibrq9m.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| CNAME-Query sends a valid NSEC3 RR as result with the hashed owner name "msdrhcdgjhlm60rcfv13o8o10902fg28" (unhashed: *.kita-wexstrasse.de) as the Wildcard-Expansion of the Closest Encloser of the query name "vr2786lvusu4bsdv2r8ol3gpbeso2pml". So the Wildcard-Expansion of the Closest Encloser confirms that the query name is generated via wildcard expansion (NoError instead of NXDomain).
Bitmap: A, RRSIG Validated: RRSIG-Owner msdrhcdgjhlm60rcfv13o8o10902fg28.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| CNAME-Query sends a valid NSEC3 RR as result with the owner name "r117f23lhdvvg02ut2k88m2s78kcj7bs" greater the NextOwner-Name "2100cslnrdbd4smi643opp629br558bh", so the NSEC3 covers the end of the zone. The hashed query name "vr2786lvusu4bsdv2r8ol3gpbeso2pml" comes after the hashed Owner, so the zone confirmes the not-existence of that CNAME RR.
Bitmap: No Bitmap? Validated: RRSIG-Owner r117f23lhdvvg02ut2k88m2s78kcj7bs.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TXT-Query sends a valid NSEC3 RR as result with the hashed owner name "m6lp8gm0tc7tspq2ps9f30bc9iibrq9m" (unhashed: kita-wexstrasse.de). So that's the Closest Encloser of the query name.
Bitmap: A, NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner m6lp8gm0tc7tspq2ps9f30bc9iibrq9m.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TXT-Query sends a valid NSEC3 RR as result with the hashed owner name "msdrhcdgjhlm60rcfv13o8o10902fg28" (unhashed: *.kita-wexstrasse.de) as the Wildcard-Expansion of the Closest Encloser of the query name "vr2786lvusu4bsdv2r8ol3gpbeso2pml". So the Wildcard-Expansion of the Closest Encloser confirms that the query name is generated via wildcard expansion (NoError instead of NXDomain).
Bitmap: A, RRSIG Validated: RRSIG-Owner msdrhcdgjhlm60rcfv13o8o10902fg28.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TXT-Query sends a valid NSEC3 RR as result with the owner name "r117f23lhdvvg02ut2k88m2s78kcj7bs" greater the NextOwner-Name "2100cslnrdbd4smi643opp629br558bh", so the NSEC3 covers the end of the zone. The hashed query name "vr2786lvusu4bsdv2r8ol3gpbeso2pml" comes after the hashed Owner, so the zone confirmes the not-existence of that TXT RR.
Bitmap: No Bitmap? Validated: RRSIG-Owner r117f23lhdvvg02ut2k88m2s78kcj7bs.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| AAAA-Query sends a valid NSEC3 RR as result with the hashed owner name "m6lp8gm0tc7tspq2ps9f30bc9iibrq9m" (unhashed: kita-wexstrasse.de). So that's the Closest Encloser of the query name.
Bitmap: A, NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner m6lp8gm0tc7tspq2ps9f30bc9iibrq9m.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| AAAA-Query sends a valid NSEC3 RR as result with the hashed owner name "msdrhcdgjhlm60rcfv13o8o10902fg28" (unhashed: *.kita-wexstrasse.de) as the Wildcard-Expansion of the Closest Encloser of the query name "vr2786lvusu4bsdv2r8ol3gpbeso2pml". So the Wildcard-Expansion of the Closest Encloser confirms that the query name is generated via wildcard expansion (NoError instead of NXDomain).
Bitmap: A, RRSIG Validated: RRSIG-Owner msdrhcdgjhlm60rcfv13o8o10902fg28.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| AAAA-Query sends a valid NSEC3 RR as result with the owner name "r117f23lhdvvg02ut2k88m2s78kcj7bs" greater the NextOwner-Name "2100cslnrdbd4smi643opp629br558bh", so the NSEC3 covers the end of the zone. The hashed query name "vr2786lvusu4bsdv2r8ol3gpbeso2pml" comes after the hashed Owner, so the zone confirmes the not-existence of that AAAA RR.
Bitmap: No Bitmap? Validated: RRSIG-Owner r117f23lhdvvg02ut2k88m2s78kcj7bs.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TLSA-Query (_443._tcp.www.kita-wexstrasse.de) sends a valid NSEC3 RR as result with the hashed owner name "m6lp8gm0tc7tspq2ps9f30bc9iibrq9m" (unhashed: kita-wexstrasse.de). So that's the Closest Encloser of the query name.
Bitmap: A, NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner m6lp8gm0tc7tspq2ps9f30bc9iibrq9m.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Next Closer Name "vr2786lvusu4bsdv2r8ol3gpbeso2pml" (unhashed: www.kita-wexstrasse.de) with the owner "r117f23lhdvvg02ut2k88m2s78kcj7bs" and the NextOwner "2100cslnrdbd4smi643opp629br558bh". So that NSEC3 confirms the not-existence of the Next Closer Name.
Bitmap: No Bitmap? Validated: RRSIG-Owner r117f23lhdvvg02ut2k88m2s78kcj7bs.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TLSA-Query sends a valid NSEC3 RR as result with the hashed owner name "msdrhcdgjhlm60rcfv13o8o10902fg28" (unhashed: *.kita-wexstrasse.de) as the Wildcard-Expansion of the Closest Encloser of the query name "7nbtgunq22ne0v90117ck459gq26iu13". So the Wildcard-Expansion of the Closest Encloser confirms that the query name is generated via wildcard expansion (NoError instead of NXDomain).
Bitmap: A, RRSIG Validated: RRSIG-Owner msdrhcdgjhlm60rcfv13o8o10902fg28.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| CAA-Query sends a valid NSEC3 RR as result with the hashed owner name "m6lp8gm0tc7tspq2ps9f30bc9iibrq9m" (unhashed: kita-wexstrasse.de). So that's the Closest Encloser of the query name.
Bitmap: A, NS, SOA, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner m6lp8gm0tc7tspq2ps9f30bc9iibrq9m.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| CAA-Query sends a valid NSEC3 RR as result with the hashed owner name "msdrhcdgjhlm60rcfv13o8o10902fg28" (unhashed: *.kita-wexstrasse.de) as the Wildcard-Expansion of the Closest Encloser of the query name "vr2786lvusu4bsdv2r8ol3gpbeso2pml". So the Wildcard-Expansion of the Closest Encloser confirms that the query name is generated via wildcard expansion (NoError instead of NXDomain).
Bitmap: A, RRSIG Validated: RRSIG-Owner msdrhcdgjhlm60rcfv13o8o10902fg28.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| CAA-Query sends a valid NSEC3 RR as result with the owner name "r117f23lhdvvg02ut2k88m2s78kcj7bs" greater the NextOwner-Name "2100cslnrdbd4smi643opp629br558bh", so the NSEC3 covers the end of the zone. The hashed query name "vr2786lvusu4bsdv2r8ol3gpbeso2pml" comes after the hashed Owner, so the zone confirmes the not-existence of that CAA RR.
Bitmap: No Bitmap? Validated: RRSIG-Owner r117f23lhdvvg02ut2k88m2s78kcj7bs.kita-wexstrasse.de., Algorithm: 8, 3 Labels, original TTL: 86400 sec, Signature-expiration: 16.07.2024, 12:50:00 +, Signature-Inception: 15.06.2024, 12:50:00 +, KeyTag 10513, Signer-Name: kita-wexstrasse.de
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|