Zone (*) DNSSEC - Informations Zone : (root)(root) 1 DS RR published DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=
• Status: Valid because published2 DNSKEY RR found Public Key with Algorithm 8, KeyTag 951, Flags 256
Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 11.02.2023, 00:00:00 +, Signature-Inception: 21.01.2023, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : nlnl 1 DS RR in the parent zone found DS with Algorithm 8, KeyTag 34112, DigestType 2 and Digest PFtfmzVXRVxQdRqb6evpI4yI4Z9fB/kwl2kXtRuVzSI=
1 RRSIG RR to validate DS RR found RRSIG-Owner nl., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 06.02.2023, 17:00:00 +, Signature-Inception: 24.01.2023, 16:00:00 +, KeyTag 951, Signer-Name: (root)
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 951 used to validate the DS RRSet in the parent zone2 DNSKEY RR found Public Key with Algorithm 8, KeyTag 34112, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 8, KeyTag 52584, Flags 256
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner nl., Algorithm: 8, 1 Labels, original TTL: 3600 sec, Signature-expiration: 04.02.2023, 14:16:59 +, Signature-Inception: 21.01.2023, 15:07:32 +, KeyTag 34112, Signer-Name: nl
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 34112 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 34112, DigestType 2 and Digest "PFtfmzVXRVxQdRqb6evpI4yI4Z9fB/kwl2kXtRuVzSI=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : larsvantol.nllarsvantol.nl 1 DS RR in the parent zone found DS with Algorithm 13, KeyTag 58938, DigestType 2 and Digest t5D9BR0mEJvN03dELtwjnXf4LsiPpyR448mzyTUOTxY=
1 RRSIG RR to validate DS RR found RRSIG-Owner larsvantol.nl., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 04.02.2023, 20:48:44 +, Signature-Inception: 21.01.2023, 07:37:31 +, KeyTag 52584, Signer-Name: nl
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 52584 used to validate the DS RRSet in the parent zone1 DNSKEY RR found Public Key with Algorithm 13, KeyTag 58938, Flags 257 (SEP = Secure Entry Point)
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner larsvantol.nl., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 58938 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 58938, DigestType 2 and Digest "t5D9BR0mEJvN03dELtwjnXf4LsiPpyR448mzyTUOTxY=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneRRSIG Type 1 validates the A - Result: 87.214.218.110 Validated: RRSIG-Owner larsvantol.nl., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
RRSIG Type 16 validates the TXT - Result: v=spf1 a mx include:spf.mijndomeinhosting.nl -all Validated: RRSIG-Owner larsvantol.nl., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
CNAME-Query sends a valid NSEC RR as result with the query name "larsvantol.nl" equal the NSEC-owner "larsvantol.nl" and the NextOwner "*.larsvantol.nl". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).Bitmap: A, NS, SOA, TXT, RRSIG, NSEC, DNSKEY Validated: RRSIG-Owner larsvantol.nl., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
Status: Good. NoData-Proof required and found. AAAA-Query sends a valid NSEC RR as result with the query name "larsvantol.nl" equal the NSEC-owner "larsvantol.nl" and the NextOwner "*.larsvantol.nl". So the zone confirmes the not-existence of that AAAA RR, but the existence of that query name (minimal one RR with that name exists).Bitmap: A, NS, SOA, TXT, RRSIG, NSEC, DNSKEY Validated: RRSIG-Owner larsvantol.nl., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
Status: Good. NoData-Proof required and found. TLSA-Query sends a valid NSEC RR as result with the owner name *.larsvantol.nl as the Wildcard-Expansion of the Closest Encloser of the query name "_443._tcp.larsvantol.nl". So the Wildcard-Expansion of the Closest Encloser confirms that the query name is generated via wildcard expansion (NoError instead of NXDomain). Bitmap: A, RRSIG, NSEC Validated: RRSIG-Owner *.larsvantol.nl., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
Status: Good. NoData-Proof required and found. TLSA-Query (_443._tcp.larsvantol.nl) sends a valid NSEC RR as result with the query name "_443._tcp.larsvantol.nl" between the NSEC-owner "_dmarc.larsvantol.nl" and the NextOwner "larsvantol.nl". So the zone confirmes the not-existence of that TLSA RR.TLSA-Query (_443._tcp.larsvantol.nl) sends a valid NSEC RR as result with the parent Wildcard "*._tcp.larsvantol.nl" between the NSEC-owner "_dmarc.larsvantol.nl" and the NextOwner "larsvantol.nl". So the zone confirmes the not-existence of that Wildcard-expansion.Bitmap: CNAME, RRSIG, NSEC Validated: RRSIG-Owner _dmarc.larsvantol.nl., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
Status: Good. NoData-Proof required and found. CAA-Query sends a valid NSEC RR as result with the query name "larsvantol.nl" equal the NSEC-owner "larsvantol.nl" and the NextOwner "*.larsvantol.nl". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).Bitmap: A, NS, SOA, TXT, RRSIG, NSEC, DNSKEY Validated: RRSIG-Owner larsvantol.nl., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
Status: Good. NoData-Proof required and found. Zone : www.larsvantol.nlwww.larsvantol.nl 0 DS RR in the parent zone found DS-Query in the parent zone has a valid NSEC RR as result with the domain name between the NSEC-Owner "*.larsvantol.nl" and the NextOwner "_dmarc.larsvantol.nl". So the parent zone confirmes the non-existence of a DS RR.Bitmap: A, RRSIG, NSEC
DS-Query in the parent zone has a valid NSEC RR as result with the domain name between the NSEC-Owner "_dmarc.larsvantol.nl" and the NextOwner "larsvantol.nl". So the parent zone confirmes the non-existence of a DS RR.Bitmap: CNAME, RRSIG, NSEC
RRSIG Type 1 validates the A - Result: 87.214.218.110. RRSIG Owner has 3 labels, RRSIG Labels = 2, so it's a wildcard expansion, the Query Name doesn't exists. An additional NSEC/NSEC3 is required to confirm the Not-Existence of the query name. Validated: RRSIG-Owner www.larsvantol.nl., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
A-Query sends a valid NSEC RR as result with the query name "www.larsvantol.nl" between the NSEC-owner "_dmarc.larsvantol.nl" and the NextOwner "larsvantol.nl". So the zone confirmes the not-existence of that A RR.Bitmap: CNAME, RRSIG, NSEC Validated: RRSIG-Owner _dmarc.larsvantol.nl., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
Status: Good. NoData-Proof required and found. CNAME-Query sends a valid NSEC RR as result with the owner name *.larsvantol.nl as the Wildcard-Expansion of the Closest Encloser of the query name "www.larsvantol.nl". So the Wildcard-Expansion of the Closest Encloser confirms that the query name is generated via wildcard expansion (NoError instead of NXDomain). Bitmap: A, RRSIG, NSEC Validated: RRSIG-Owner *.larsvantol.nl., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
Status: Good. NoData-Proof required and found. CNAME-Query sends a valid NSEC RR as result with the query name "www.larsvantol.nl" between the NSEC-owner "_dmarc.larsvantol.nl" and the NextOwner "larsvantol.nl". So the zone confirmes the not-existence of that CNAME RR.Bitmap: CNAME, RRSIG, NSEC Validated: RRSIG-Owner _dmarc.larsvantol.nl., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
Status: Good. NoData-Proof required and found. TXT-Query sends a valid NSEC RR as result with the owner name *.larsvantol.nl as the Wildcard-Expansion of the Closest Encloser of the query name "www.larsvantol.nl". So the Wildcard-Expansion of the Closest Encloser confirms that the query name is generated via wildcard expansion (NoError instead of NXDomain). Bitmap: A, RRSIG, NSEC Validated: RRSIG-Owner *.larsvantol.nl., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
Status: Good. NoData-Proof required and found. TXT-Query sends a valid NSEC RR as result with the query name "www.larsvantol.nl" between the NSEC-owner "_dmarc.larsvantol.nl" and the NextOwner "larsvantol.nl". So the zone confirmes the not-existence of that TXT RR.Bitmap: CNAME, RRSIG, NSEC Validated: RRSIG-Owner _dmarc.larsvantol.nl., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
Status: Good. NoData-Proof required and found. AAAA-Query sends a valid NSEC RR as result with the owner name *.larsvantol.nl as the Wildcard-Expansion of the Closest Encloser of the query name "www.larsvantol.nl". So the Wildcard-Expansion of the Closest Encloser confirms that the query name is generated via wildcard expansion (NoError instead of NXDomain). Bitmap: A, RRSIG, NSEC Validated: RRSIG-Owner *.larsvantol.nl., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
Status: Good. NoData-Proof required and found. AAAA-Query sends a valid NSEC RR as result with the query name "www.larsvantol.nl" between the NSEC-owner "_dmarc.larsvantol.nl" and the NextOwner "larsvantol.nl". So the zone confirmes the not-existence of that AAAA RR.Bitmap: CNAME, RRSIG, NSEC Validated: RRSIG-Owner _dmarc.larsvantol.nl., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
Status: Good. NoData-Proof required and found. TLSA-Query sends a valid NSEC RR as result with the owner name *.larsvantol.nl as the Wildcard-Expansion of the Closest Encloser of the query name "_443._tcp.www.larsvantol.nl". So the Wildcard-Expansion of the Closest Encloser confirms that the query name is generated via wildcard expansion (NoError instead of NXDomain). Bitmap: A, RRSIG, NSEC Validated: RRSIG-Owner *.larsvantol.nl., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
Status: Good. NoData-Proof required and found. TLSA-Query (_443._tcp.www.larsvantol.nl) sends a valid NSEC RR as result with the query name "_443._tcp.www.larsvantol.nl" between the NSEC-owner "_dmarc.larsvantol.nl" and the NextOwner "larsvantol.nl". So the zone confirmes the not-existence of that TLSA RR.TLSA-Query (_443._tcp.www.larsvantol.nl) sends a valid NSEC RR as result with the parent Wildcard "*._tcp.www.larsvantol.nl" between the NSEC-owner "_dmarc.larsvantol.nl" and the NextOwner "larsvantol.nl". So the zone confirmes the not-existence of that Wildcard-expansion.Bitmap: CNAME, RRSIG, NSEC Validated: RRSIG-Owner _dmarc.larsvantol.nl., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
Status: Good. NoData-Proof required and found. CAA-Query sends a valid NSEC RR as result with the owner name *.larsvantol.nl as the Wildcard-Expansion of the Closest Encloser of the query name "www.larsvantol.nl". So the Wildcard-Expansion of the Closest Encloser confirms that the query name is generated via wildcard expansion (NoError instead of NXDomain). Bitmap: A, RRSIG, NSEC Validated: RRSIG-Owner *.larsvantol.nl., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
Status: Good. NoData-Proof required and found. CAA-Query sends a valid NSEC RR as result with the query name "www.larsvantol.nl" between the NSEC-owner "_dmarc.larsvantol.nl" and the NextOwner "larsvantol.nl". So the zone confirmes the not-existence of that CAA RR.Bitmap: CNAME, RRSIG, NSEC Validated: RRSIG-Owner _dmarc.larsvantol.nl., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 02.02.2023, 00:00:00 +, Signature-Inception: 12.01.2023, 00:00:00 +, KeyTag 58938, Signer-Name: larsvantol.nl
Status: Good. NoData-Proof required and found.