| Zone (*) | DNSSEC - Informations |
|---|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 3 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 26470, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 38696, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 02.04.2025, 00:00:00 +, Signature-Inception: 12.03.2025, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: org
|
|
org
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 26974, DigestType 2 and Digest T+3ilMU/Q4oVjEHTlInNeKhr6w2KCur/FHRcDRbh3jI=
|
|
|
|
|
| 2 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner org., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 01.04.2025, 20:00:00 +, Signature-Inception: 19.03.2025, 19:00:00 +, KeyTag 26470, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 26470 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 3 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 26974, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 48111, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 63726, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner org., Algorithm: 8, 1 Labels, original TTL: 3600 sec, Signature-expiration: 07.04.2025, 15:22:56 +, Signature-Inception: 17.03.2025, 14:22:56 +, KeyTag 26974, Signer-Name: org
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 26974 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 26974, DigestType 2 and Digest "T+3ilMU/Q4oVjEHTlInNeKhr6w2KCur/FHRcDRbh3jI=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: antopie.org
|
|
antopie.org
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 15, KeyTag 48333, DigestType 2 and Digest qdi3v808EaKWHcvgvoqz49UIElv3JdggkdJNUxWLbxE=
|
|
|
|
|
| 2 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 07.04.2025, 15:22:56 +, Signature-Inception: 17.03.2025, 14:22:56 +, KeyTag 63726, Signer-Name: org
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 63726 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 15, KeyTag 48333, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 15, KeyTag 58210, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner antopie.org., Algorithm: 15, 2 Labels, original TTL: 10800 sec, Signature-expiration: 28.03.2025, 06:18:57 +, Signature-Inception: 14.03.2025, 04:48:57 +, KeyTag 48333, Signer-Name: antopie.org
|
|
|
|
|
| • Status: Good - Algorithmus 15 and DNSKEY with KeyTag 48333 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 15, KeyTag 48333, DigestType 2 and Digest "qdi3v808EaKWHcvgvoqz49UIElv3JdggkdJNUxWLbxE=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: meta.antopie.org
|
|
meta.antopie.org
| 0 DS RR in the parent zone found
|
|
|
|
|
| RRSIG Type 5 validates the CNAME - Result: yuno.antopie.org
Validated: RRSIG-Owner meta.antopie.org., Algorithm: 15, 3 Labels, original TTL: 86400 sec, Signature-expiration: 27.03.2025, 05:18:57 +, Signature-Inception: 13.03.2025, 03:48:57 +, KeyTag 58210, Signer-Name: antopie.org
|
|
|
Zone: www.meta.antopie.org
|
|
www.meta.antopie.org
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "ovlloa0l1h38usl5gkkv67pt1utp6bha" between the hashed NSEC3-owner "ot6jcfstvm4c1b7kveba7s21o2e7mg15" and the hashed NextOwner "ovn30nujdvv3un06vf5shh5148stm2ch". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: No Bitmap? Validated: RRSIG-Owner ot6jcfstvm4c1b7kveba7s21o2e7mg15.antopie.org., Algorithm: 15, 3 Labels, original TTL: 10800 sec, Signature-expiration: 27.03.2025, 05:18:57 +, Signature-Inception: 13.03.2025, 03:48:57 +, KeyTag 58210, Signer-Name: antopie.org
|
|
|
|
|
| DS-Query in the parent zone sends valid NSEC3 RR with the Hash "hs5iq46os8ncb7i3phtnp62eg4mi02vc" as Owner. That's the Hash of "meta.antopie.org" with the NextHashedOwnerName "ht628qbjkhuhnrbckks52qepb9rpp6vc". So that domain name is the Closest Encloser of "www.meta.antopie.org". Opt-Out: False.
Bitmap: CNAME, RRSIG Validated: RRSIG-Owner hs5iq46os8ncb7i3phtnp62eg4mi02vc.antopie.org., Algorithm: 15, 3 Labels, original TTL: 10800 sec, Signature-expiration: 27.03.2025, 05:18:57 +, Signature-Inception: 13.03.2025, 03:48:57 +, KeyTag 58210, Signer-Name: antopie.org
|
|
|
|
|
| The ClosestEncloser says, that "*.meta.antopie.org" with the Hash "eb6efb4kivt3amt2r3i05oaf02h5ci95" is a possible Wildcard of the DS Query Name. But the DS-Query in the parent zone sends a valid NSEC3 RR With the owner "e3sam8c5fpodvr7k3vloj71nkfn2jni3" and the Next Owner "ejbj8acjul995799mc0id3gsiclims4q", so the Hash of the wildcard is between these hashes. So that NSEC3 proves the Not-existence of that wildcard expansion. Opt-Out: False.
Bitmap: CNAME, RRSIG Validated: RRSIG-Owner e3sam8c5fpodvr7k3vloj71nkfn2jni3.antopie.org., Algorithm: 15, 3 Labels, original TTL: 10800 sec, Signature-expiration: 27.03.2025, 05:18:57 +, Signature-Inception: 13.03.2025, 03:48:57 +, KeyTag 58210, Signer-Name: antopie.org
|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 3 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 26470, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 38696, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 02.04.2025, 00:00:00 +, Signature-Inception: 12.03.2025, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: org
|
|
org
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 26974, DigestType 2 and Digest T+3ilMU/Q4oVjEHTlInNeKhr6w2KCur/FHRcDRbh3jI=
|
|
|
|
|
| 2 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner org., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 01.04.2025, 20:00:00 +, Signature-Inception: 19.03.2025, 19:00:00 +, KeyTag 26470, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 26470 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 3 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 26974, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 48111, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 63726, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner org., Algorithm: 8, 1 Labels, original TTL: 3600 sec, Signature-expiration: 07.04.2025, 15:22:56 +, Signature-Inception: 17.03.2025, 14:22:56 +, KeyTag 26974, Signer-Name: org
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 26974 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 26974, DigestType 2 and Digest "T+3ilMU/Q4oVjEHTlInNeKhr6w2KCur/FHRcDRbh3jI=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: antopie.org
|
|
antopie.org
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 15, KeyTag 48333, DigestType 2 and Digest qdi3v808EaKWHcvgvoqz49UIElv3JdggkdJNUxWLbxE=
|
|
|
|
|
| 2 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner antopie.org., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 07.04.2025, 15:22:56 +, Signature-Inception: 17.03.2025, 14:22:56 +, KeyTag 63726, Signer-Name: org
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 63726 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 15, KeyTag 48333, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 15, KeyTag 58210, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner antopie.org., Algorithm: 15, 2 Labels, original TTL: 10800 sec, Signature-expiration: 28.03.2025, 06:18:57 +, Signature-Inception: 14.03.2025, 04:48:57 +, KeyTag 48333, Signer-Name: antopie.org
|
|
|
|
|
| • Status: Good - Algorithmus 15 and DNSKEY with KeyTag 48333 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 15, KeyTag 48333, DigestType 2 and Digest "qdi3v808EaKWHcvgvoqz49UIElv3JdggkdJNUxWLbxE=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: yuno.antopie.org
|
|
yuno.antopie.org
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "b150fhjvd7h96cmijj5a94op1lu4v2cq" between the hashed NSEC3-owner "b150fhjvd7h96cmijj5a94op1lu4v2cq" and the hashed NextOwner "b2v0kqjqkasm29hol8akf84b5frm0gcb". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: A, TXT, AAAA, RRSIG Validated: RRSIG-Owner b150fhjvd7h96cmijj5a94op1lu4v2cq.antopie.org., Algorithm: 15, 3 Labels, original TTL: 10800 sec, Signature-expiration: 27.03.2025, 05:18:57 +, Signature-Inception: 13.03.2025, 03:48:57 +, KeyTag 58210, Signer-Name: antopie.org
|
|
|
|
|
| 0 DNSKEY RR found
|
|
|
|
|
|
|
|
|
|
|
| RRSIG Type 1 validates the A - Result: 78.194.59.118
Validated: RRSIG-Owner yuno.antopie.org., Algorithm: 15, 3 Labels, original TTL: 10800 sec, Signature-expiration: 27.03.2025, 05:18:57 +, Signature-Inception: 13.03.2025, 03:48:57 +, KeyTag 58210, Signer-Name: antopie.org
|
|
|
|
|
| RRSIG Type 16 validates the TXT - Result: v=spf1 a mx -all
Validated: RRSIG-Owner yuno.antopie.org., Algorithm: 15, 3 Labels, original TTL: 86400 sec, Signature-expiration: 27.03.2025, 05:18:57 +, Signature-Inception: 13.03.2025, 03:48:57 +, KeyTag 58210, Signer-Name: antopie.org
|
|
|
|
|
| RRSIG Type 28 validates the AAAA - Result: 2A01:0E34:EC23:B760:ACAB:0003:0003:0003
Validated: RRSIG-Owner yuno.antopie.org., Algorithm: 15, 3 Labels, original TTL: 10800 sec, Signature-expiration: 27.03.2025, 05:18:57 +, Signature-Inception: 13.03.2025, 03:48:57 +, KeyTag 58210, Signer-Name: antopie.org
|
|
|
|
|
| RRSIG Type 52 validates the TLSA - Result (_443._tcp.yuno.antopie.org): _443._tcp.yuno.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 025490860b498ab73c6a12f27a49ad5fe230fafe3ac8f6112c9b7d0aad46941d
_443._tcp.yuno.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 2bbad93ab5c79279ec121507f272cbe0c6647a3aae52e22f388afab426b4adba
_443._tcp.yuno.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 6ddac18698f7f1f7e1c69b9bce420d974ac6f94ca8b2c761701623f99c767dc7
_443._tcp.yuno.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: 919c0df7a787b597ed056ace654b1de9c0387acf349f73734a4fd7b58cf612a4
_443._tcp.yuno.antopie.org: CertUsage 2 (DANE-TA, Trust anchor assertion), Selector: 1 (SPKI, SubjectPublicKeyInfo), Matching: 1 (SHA2-256, 256 bit hash by SHA2), CertificateAssociationData: f1647a5ee3efac54c892e930584fe47979b7acd1c76c1271bca1c5076d869888
Validated: RRSIG-Owner _letsencrypt._dane.antopie.org., Algorithm: 15, 4 Labels, original TTL: 86400 sec, Signature-expiration: 27.03.2025, 05:18:57 +, Signature-Inception: 13.03.2025, 03:48:57 +, KeyTag 58210, Signer-Name: antopie.org
|
|
|
|
|
| RRSIG Type 5 validates the TLSA - Result (_443._tcp.yuno.antopie.org): _letsencrypt._dane.antopie.org. That's a CNAME answer
Validated: RRSIG-Owner _443._tcp.yuno.antopie.org., Algorithm: 15, 5 Labels, original TTL: 86400 sec, Signature-expiration: 27.03.2025, 05:18:57 +, Signature-Inception: 13.03.2025, 03:48:57 +, KeyTag 58210, Signer-Name: antopie.org
|
|
|
|
|
| CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "b150fhjvd7h96cmijj5a94op1lu4v2cq" equal the hashed NSEC3-owner "b150fhjvd7h96cmijj5a94op1lu4v2cq" and the hashed NextOwner "b2v0kqjqkasm29hol8akf84b5frm0gcb". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, TXT, AAAA, RRSIG Validated: RRSIG-Owner b150fhjvd7h96cmijj5a94op1lu4v2cq.antopie.org., Algorithm: 15, 3 Labels, original TTL: 10800 sec, Signature-expiration: 27.03.2025, 05:18:57 +, Signature-Inception: 13.03.2025, 03:48:57 +, KeyTag 58210, Signer-Name: antopie.org
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| CAA-Query sends a valid NSEC3 RR as result with the hashed query name "b150fhjvd7h96cmijj5a94op1lu4v2cq" equal the hashed NSEC3-owner "b150fhjvd7h96cmijj5a94op1lu4v2cq" and the hashed NextOwner "b2v0kqjqkasm29hol8akf84b5frm0gcb". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, TXT, AAAA, RRSIG Validated: RRSIG-Owner b150fhjvd7h96cmijj5a94op1lu4v2cq.antopie.org., Algorithm: 15, 3 Labels, original TTL: 10800 sec, Signature-expiration: 27.03.2025, 05:18:57 +, Signature-Inception: 13.03.2025, 03:48:57 +, KeyTag 58210, Signer-Name: antopie.org
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|