Zone (*) | DNSSEC - Informations |
---|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 14631, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 11.06.2021, 00:00:00 +, Signature-Inception: 21.05.2021, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: be
|
|
be
| 2 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 12664, DigestType 2 and Digest dRQemxGIqVp6hVv0fieKdCpePy3e7Y6ZXXSdSPLw5y0=
|
|
|
|
|
| DS with Algorithm 8, KeyTag 52756, DigestType 2 and Digest VIWsM918ftI36ipL0mlzHIFpYP4YEEICRIS1zspuzJ8=
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner be., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 06.06.2021, 05:00:00 +, Signature-Inception: 24.05.2021, 04:00:00 +, KeyTag 14631, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 14631 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 5 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 5955, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 12664, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 46794, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 52756, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 59085, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner be., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 05.07.2021, 15:15:29 +, Signature-Inception: 18.03.2021, 09:22:23 +, KeyTag 52756, Signer-Name: be
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 52756 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 52756, DigestType 2 and Digest "VIWsM918ftI36ipL0mlzHIFpYP4YEEICRIS1zspuzJ8=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: royalphotonarlon.be
|
|
royalphotonarlon.be
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 35815, DigestType 2 and Digest jeiN/GDu1E8LA6Wew0tT2w71t/X4OtqI6j7hUgt1Pwk=
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner royalphotonarlon.be., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 10.06.2021, 05:26:55 +, Signature-Inception: 20.05.2021, 10:40:43 +, KeyTag 59085, Signer-Name: be
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 59085 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 35815, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 50613, Flags 256
|
|
|
|
|
| 2 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner royalphotonarlon.be., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 11.06.2021, 20:07:38 +, Signature-Inception: 12.05.2021, 20:07:38 +, KeyTag 35815, Signer-Name: royalphotonarlon.be
|
|
|
|
|
| RRSIG-Owner royalphotonarlon.be., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 11.06.2021, 20:07:38 +, Signature-Inception: 12.05.2021, 20:07:38 +, KeyTag 50613, Signer-Name: royalphotonarlon.be
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 35815 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 50613 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 35815, DigestType 2 and Digest "jeiN/GDu1E8LA6Wew0tT2w71t/X4OtqI6j7hUgt1Pwk=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| RRSIG Type 1 validates the A - Result: 213.186.33.40
Validated: RRSIG-Owner royalphotonarlon.be., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 11.06.2021, 20:07:38 +, Signature-Inception: 12.05.2021, 20:07:38 +, KeyTag 50613, Signer-Name: royalphotonarlon.be
|
|
|
|
|
| RRSIG Type 16 validates the TXT - Result: v=spf1 include:mx.ovh.com ~all
Validated: RRSIG-Owner royalphotonarlon.be., Algorithm: 8, 2 Labels, original TTL: 600 sec, Signature-expiration: 11.06.2021, 20:07:38 +, Signature-Inception: 12.05.2021, 20:07:38 +, KeyTag 50613, Signer-Name: royalphotonarlon.be
|
|
|
|
|
| CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "6g0p3ulq3s5p9urbn8g55su6olv2rpop" equal the hashed NSEC3-owner "6g0p3ulq3s5p9urbn8g55su6olv2rpop" and the hashed NextOwner "70v2k1kd7g3rrkfrfp1eapptkg5riom0". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner 6g0p3ulq3s5p9urbn8g55su6olv2rpop.royalphotonarlon.be., Algorithm: 8, 3 Labels, original TTL: 300 sec, Signature-expiration: 11.06.2021, 20:07:38 +, Signature-Inception: 12.05.2021, 20:07:38 +, KeyTag 50613, Signer-Name: royalphotonarlon.be
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| AAAA-Query sends a valid NSEC3 RR as result with the hashed query name "6g0p3ulq3s5p9urbn8g55su6olv2rpop" equal the hashed NSEC3-owner "6g0p3ulq3s5p9urbn8g55su6olv2rpop" and the hashed NextOwner "70v2k1kd7g3rrkfrfp1eapptkg5riom0". So the zone confirmes the not-existence of that AAAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner 6g0p3ulq3s5p9urbn8g55su6olv2rpop.royalphotonarlon.be., Algorithm: 8, 3 Labels, original TTL: 300 sec, Signature-expiration: 11.06.2021, 20:07:38 +, Signature-Inception: 12.05.2021, 20:07:38 +, KeyTag 50613, Signer-Name: royalphotonarlon.be
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TLSA-Query (_443._tcp.royalphotonarlon.be) sends a valid NSEC3 RR as result with the hashed owner name "g8en72vdu7sac6pte4cdltr9vfg4k09b" (unhashed: _tcp.royalphotonarlon.be). So that's the Closest Encloser of the query name.
Bitmap: No Bitmap? Validated: RRSIG-Owner g8en72vdu7sac6pte4cdltr9vfg4k09b.royalphotonarlon.be., Algorithm: 8, 3 Labels, original TTL: 300 sec, Signature-expiration: 11.06.2021, 20:07:38 +, Signature-Inception: 12.05.2021, 20:07:38 +, KeyTag 50613, Signer-Name: royalphotonarlon.be
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| TLSA-Query (_443._tcp.royalphotonarlon.be) sends a valid NSEC3 RR as result with the hashed query name "1omep06peq6hr4hgoiellvalgs8iq5of" between the hashed NSEC3-owner "0moe93hsrghpgsvtkugg8t9f0k0cnehm" and the hashed NextOwner "209ufpt36oo7sr49ll4lddd7codi349e". So the zone confirmes the not-existence of that TLSA RR.
Bitmap: SRV, RRSIG Validated: RRSIG-Owner 0moe93hsrghpgsvtkugg8t9f0k0cnehm.royalphotonarlon.be., Algorithm: 8, 3 Labels, original TTL: 300 sec, Signature-expiration: 11.06.2021, 20:07:38 +, Signature-Inception: 12.05.2021, 20:07:38 +, KeyTag 50613, Signer-Name: royalphotonarlon.be
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Wildcard expansion of the ClosestEncloser "fhdj010kqkctohk2aeadv1fudqa3iu33" (unhashed: *._tcp.royalphotonarlon.be) with the owner "fcrka9dhdpod5pbbm05atcpurpbea7e5" and the NextOwner "g6qtuv2elmp78d75vtkeq06cp4tnchua". So that NSEC3 confirms the not-existence of the Wildcard expansion.
Bitmap: CNAME, RRSIG Validated: RRSIG-Owner fcrka9dhdpod5pbbm05atcpurpbea7e5.royalphotonarlon.be., Algorithm: 8, 3 Labels, original TTL: 300 sec, Signature-expiration: 11.06.2021, 20:07:38 +, Signature-Inception: 12.05.2021, 20:07:38 +, KeyTag 50613, Signer-Name: royalphotonarlon.be
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| CAA-Query sends a valid NSEC3 RR as result with the hashed query name "6g0p3ulq3s5p9urbn8g55su6olv2rpop" equal the hashed NSEC3-owner "6g0p3ulq3s5p9urbn8g55su6olv2rpop" and the hashed NextOwner "70v2k1kd7g3rrkfrfp1eapptkg5riom0". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner 6g0p3ulq3s5p9urbn8g55su6olv2rpop.royalphotonarlon.be., Algorithm: 8, 3 Labels, original TTL: 300 sec, Signature-expiration: 11.06.2021, 20:07:38 +, Signature-Inception: 12.05.2021, 20:07:38 +, KeyTag 50613, Signer-Name: royalphotonarlon.be
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
Zone: www.royalphotonarlon.be
|
|
www.royalphotonarlon.be
| 0 DS RR in the parent zone found
|
|
|
|
|
| RRSIG Type 1 validates the A - Result: 213.186.33.40
Validated: RRSIG-Owner www.royalphotonarlon.be., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 11.06.2021, 20:07:38 +, Signature-Inception: 12.05.2021, 20:07:38 +, KeyTag 50613, Signer-Name: royalphotonarlon.be
|
|
|
|
|
| CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "ruconbvpo6lbgou4tq7f68iq4m5f7soj" equal the hashed NSEC3-owner "ruconbvpo6lbgou4tq7f68iq4m5f7soj" and the hashed NextOwner "0moe93hsrghpgsvtkugg8t9f0k0cnehm". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, MX, RRSIG Validated: RRSIG-Owner ruconbvpo6lbgou4tq7f68iq4m5f7soj.royalphotonarlon.be., Algorithm: 8, 3 Labels, original TTL: 300 sec, Signature-expiration: 11.06.2021, 20:07:38 +, Signature-Inception: 12.05.2021, 20:07:38 +, KeyTag 50613, Signer-Name: royalphotonarlon.be
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TXT-Query sends a valid NSEC3 RR as result with the hashed query name "ruconbvpo6lbgou4tq7f68iq4m5f7soj" equal the hashed NSEC3-owner "ruconbvpo6lbgou4tq7f68iq4m5f7soj" and the hashed NextOwner "0moe93hsrghpgsvtkugg8t9f0k0cnehm". So the zone confirmes the not-existence of that TXT RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, MX, RRSIG Validated: RRSIG-Owner ruconbvpo6lbgou4tq7f68iq4m5f7soj.royalphotonarlon.be., Algorithm: 8, 3 Labels, original TTL: 300 sec, Signature-expiration: 11.06.2021, 20:07:38 +, Signature-Inception: 12.05.2021, 20:07:38 +, KeyTag 50613, Signer-Name: royalphotonarlon.be
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| AAAA-Query sends a valid NSEC3 RR as result with the hashed query name "ruconbvpo6lbgou4tq7f68iq4m5f7soj" equal the hashed NSEC3-owner "ruconbvpo6lbgou4tq7f68iq4m5f7soj" and the hashed NextOwner "0moe93hsrghpgsvtkugg8t9f0k0cnehm". So the zone confirmes the not-existence of that AAAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, MX, RRSIG Validated: RRSIG-Owner ruconbvpo6lbgou4tq7f68iq4m5f7soj.royalphotonarlon.be., Algorithm: 8, 3 Labels, original TTL: 300 sec, Signature-expiration: 11.06.2021, 20:07:38 +, Signature-Inception: 12.05.2021, 20:07:38 +, KeyTag 50613, Signer-Name: royalphotonarlon.be
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TLSA-Query (_443._tcp.www.royalphotonarlon.be) sends a valid NSEC3 RR as result with the hashed owner name "ruconbvpo6lbgou4tq7f68iq4m5f7soj" (unhashed: www.royalphotonarlon.be). So that's the Closest Encloser of the query name.
Bitmap: A, MX, RRSIG Validated: RRSIG-Owner ruconbvpo6lbgou4tq7f68iq4m5f7soj.royalphotonarlon.be., Algorithm: 8, 3 Labels, original TTL: 300 sec, Signature-expiration: 11.06.2021, 20:07:38 +, Signature-Inception: 12.05.2021, 20:07:38 +, KeyTag 50613, Signer-Name: royalphotonarlon.be
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Next Closer Name "8fthn9ueg13mb0ntcjhj8bqc7ajs4k3p" (unhashed: _tcp.www.royalphotonarlon.be) with the owner "70v2k1kd7g3rrkfrfp1eapptkg5riom0" and the NextOwner "9d748n1nvsla99d8nkiq7cllncer1bhl". So that NSEC3 confirms the not-existence of the Next Closer Name.
Bitmap: CNAME, RRSIG Validated: RRSIG-Owner 70v2k1kd7g3rrkfrfp1eapptkg5riom0.royalphotonarlon.be., Algorithm: 8, 3 Labels, original TTL: 300 sec, Signature-expiration: 11.06.2021, 20:07:38 +, Signature-Inception: 12.05.2021, 20:07:38 +, KeyTag 50613, Signer-Name: royalphotonarlon.be
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Wildcard expansion of the ClosestEncloser "6a2931vb89esav3lr2qe3k3v677ppe14" (unhashed: *.www.royalphotonarlon.be) with the owner "209ufpt36oo7sr49ll4lddd7codi349e" and the NextOwner "6g0p3ulq3s5p9urbn8g55su6olv2rpop". So that NSEC3 confirms the not-existence of the Wildcard expansion. TLSA-Query (_443._tcp.www.royalphotonarlon.be) sends a valid NSEC3 RR as result with the hashed query name "3ikbmf3h9m47gt4oh2gl90ho9qqshdrd" between the hashed NSEC3-owner "209ufpt36oo7sr49ll4lddd7codi349e" and the hashed NextOwner "6g0p3ulq3s5p9urbn8g55su6olv2rpop". So the zone confirmes the not-existence of that TLSA RR.
Bitmap: SRV, RRSIG Validated: RRSIG-Owner 209ufpt36oo7sr49ll4lddd7codi349e.royalphotonarlon.be., Algorithm: 8, 3 Labels, original TTL: 300 sec, Signature-expiration: 11.06.2021, 20:07:38 +, Signature-Inception: 12.05.2021, 20:07:38 +, KeyTag 50613, Signer-Name: royalphotonarlon.be
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| CAA-Query sends a valid NSEC3 RR as result with the hashed query name "ruconbvpo6lbgou4tq7f68iq4m5f7soj" equal the hashed NSEC3-owner "ruconbvpo6lbgou4tq7f68iq4m5f7soj" and the hashed NextOwner "0moe93hsrghpgsvtkugg8t9f0k0cnehm". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, MX, RRSIG Validated: RRSIG-Owner ruconbvpo6lbgou4tq7f68iq4m5f7soj.royalphotonarlon.be., Algorithm: 8, 3 Labels, original TTL: 300 sec, Signature-expiration: 11.06.2021, 20:07:38 +, Signature-Inception: 12.05.2021, 20:07:38 +, KeyTag 50613, Signer-Name: royalphotonarlon.be
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|