Zone (*) | DNSSEC - Informations |
---|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20826, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 20.09.2022, 00:00:00 +, Signature-Inception: 30.08.2022, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: uk
|
|
uk
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 43876, DigestType 2 and Digest oQftKsG9FNkkFzvH6CehFTWCByOU+Scro34jU7xllgM=
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner uk., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 15.09.2022, 04:00:00 +, Signature-Inception: 02.09.2022, 03:00:00 +, KeyTag 20826, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20826 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 43056, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 43876, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner uk., Algorithm: 8, 1 Labels, original TTL: 3600 sec, Signature-expiration: 15.09.2022, 18:33:17 +, Signature-Inception: 01.09.2022, 18:29:36 +, KeyTag 43876, Signer-Name: uk
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 43876 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 43876, DigestType 2 and Digest "oQftKsG9FNkkFzvH6CehFTWCByOU+Scro34jU7xllgM=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: co.uk
|
|
co.uk
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 33621, DigestType 2 and Digest uRmdi3/KcQfXjEGNHRvJ6f6dm5sYe9E8ltxLZYJCXNg=
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner co.uk., Algorithm: 8, 2 Labels, original TTL: 300 sec, Signature-expiration: 15.09.2022, 22:46:29 +, Signature-Inception: 01.09.2022, 22:06:53 +, KeyTag 43056, Signer-Name: uk
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 43056 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 1 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 33621, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner co.uk., Algorithm: 8, 2 Labels, original TTL: 300 sec, Signature-expiration: 05.10.2022, 20:26:19 +, Signature-Inception: 31.08.2022, 19:58:40 +, KeyTag 33621, Signer-Name: co.uk
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 33621 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 33621, DigestType 2 and Digest "uRmdi3/KcQfXjEGNHRvJ6f6dm5sYe9E8ltxLZYJCXNg=" validates local Key with the same values
|
|
|
Zone: silverbullets.co.uk
|
|
silverbullets.co.uk
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 17404, DigestType 2 and Digest DpnQdkkeaBm5I6eYa6jcZDaiJS/z3N23X2krejwcitg=
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner silverbullets.co.uk., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 30.09.2022, 11:32:49 +, Signature-Inception: 26.08.2022, 10:55:27 +, KeyTag 33621, Signer-Name: co.uk
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 33621 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 7980, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 17404, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 2 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner silverbullets.co.uk., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 30.09.2022, 10:33:40 +, Signature-Inception: 31.08.2022, 10:33:40 +, KeyTag 7980, Signer-Name: silverbullets.co.uk
|
|
|
|
|
| RRSIG-Owner silverbullets.co.uk., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 30.09.2022, 10:33:40 +, Signature-Inception: 31.08.2022, 10:33:40 +, KeyTag 17404, Signer-Name: silverbullets.co.uk
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 7980 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 17404 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 17404, DigestType 2 and Digest "DpnQdkkeaBm5I6eYa6jcZDaiJS/z3N23X2krejwcitg=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| RRSIG Type 1 validates the A - Result: 107.175.245.18
Validated: RRSIG-Owner silverbullets.co.uk., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 30.09.2022, 10:33:40 +, Signature-Inception: 31.08.2022, 10:33:40 +, KeyTag 7980, Signer-Name: silverbullets.co.uk
|
|
|
|
|
| RRSIG Type 16 validates the TXT - Result: 1|www.silverbullets.co.uk
google-site-verification=ZEAAjR7ofIigS1jteowuFGxFMR42noEC3kTRBEerEqI
Validated: RRSIG-Owner silverbullets.co.uk., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 30.09.2022, 10:33:40 +, Signature-Inception: 31.08.2022, 10:33:40 +, KeyTag 7980, Signer-Name: silverbullets.co.uk
|
|
|
|
|
| CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "mrkhm8c93nihe2am76rrglvevc3jbgbo" equal the hashed NSEC3-owner "mrkhm8c93nihe2am76rrglvevc3jbgbo" and the hashed NextOwner "nbt9i0mbrlpdptrdkdncnefdn5c39uuj". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner mrkhm8c93nihe2am76rrglvevc3jbgbo.silverbullets.co.uk., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 30.09.2022, 10:33:40 +, Signature-Inception: 31.08.2022, 10:33:40 +, KeyTag 7980, Signer-Name: silverbullets.co.uk
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| AAAA-Query sends a valid NSEC3 RR as result with the hashed query name "mrkhm8c93nihe2am76rrglvevc3jbgbo" equal the hashed NSEC3-owner "mrkhm8c93nihe2am76rrglvevc3jbgbo" and the hashed NextOwner "nbt9i0mbrlpdptrdkdncnefdn5c39uuj". So the zone confirmes the not-existence of that AAAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner mrkhm8c93nihe2am76rrglvevc3jbgbo.silverbullets.co.uk., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 30.09.2022, 10:33:40 +, Signature-Inception: 31.08.2022, 10:33:40 +, KeyTag 7980, Signer-Name: silverbullets.co.uk
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TLSA-Query (_443._tcp.silverbullets.co.uk) sends a valid NSEC3 RR as result with the hashed owner name "gf4jn3v7c55efm8u7968d93hknak8hjk" (unhashed: _tcp.silverbullets.co.uk). So that's the Closest Encloser of the query name.
Bitmap: No Bitmap? Validated: RRSIG-Owner gf4jn3v7c55efm8u7968d93hknak8hjk.silverbullets.co.uk., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 30.09.2022, 10:33:40 +, Signature-Inception: 31.08.2022, 10:33:40 +, KeyTag 7980, Signer-Name: silverbullets.co.uk
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Wildcard expansion of the ClosestEncloser "40c8h1klfqp20bi8p7ebcshuhj8k7dt2" (unhashed: *._tcp.silverbullets.co.uk) with the owner "0aj6j48hsui9pndctkkc7qumm41jpajt" and the NextOwner "7d7i1kk0ffm96osfilkntg1ugeh0s4if". So that NSEC3 confirms the not-existence of the Wildcard expansion. TLSA-Query (_443._tcp.silverbullets.co.uk) sends a valid NSEC3 RR as result with the hashed query name "6j9q3p1st16rbonpq5vkr9fug9jp7jf5" between the hashed NSEC3-owner "0aj6j48hsui9pndctkkc7qumm41jpajt" and the hashed NextOwner "7d7i1kk0ffm96osfilkntg1ugeh0s4if". So the zone confirmes the not-existence of that TLSA RR.
Bitmap: SRV, RRSIG Validated: RRSIG-Owner 0aj6j48hsui9pndctkkc7qumm41jpajt.silverbullets.co.uk., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 30.09.2022, 10:33:40 +, Signature-Inception: 31.08.2022, 10:33:40 +, KeyTag 7980, Signer-Name: silverbullets.co.uk
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| CAA-Query sends a valid NSEC3 RR as result with the hashed query name "mrkhm8c93nihe2am76rrglvevc3jbgbo" equal the hashed NSEC3-owner "mrkhm8c93nihe2am76rrglvevc3jbgbo" and the hashed NextOwner "nbt9i0mbrlpdptrdkdncnefdn5c39uuj". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, MX, TXT, RRSIG, DNSKEY, NSEC3PARAM Validated: RRSIG-Owner mrkhm8c93nihe2am76rrglvevc3jbgbo.silverbullets.co.uk., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 30.09.2022, 10:33:40 +, Signature-Inception: 31.08.2022, 10:33:40 +, KeyTag 7980, Signer-Name: silverbullets.co.uk
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
Zone: www.silverbullets.co.uk
|
|
www.silverbullets.co.uk
| 0 DS RR in the parent zone found
|
|
|
|
|
| RRSIG Type 1 validates the A - Result: 107.175.245.18
Validated: RRSIG-Owner www.silverbullets.co.uk., Algorithm: 8, 4 Labels, original TTL: 3600 sec, Signature-expiration: 30.09.2022, 10:33:40 +, Signature-Inception: 31.08.2022, 10:33:40 +, KeyTag 7980, Signer-Name: silverbullets.co.uk
|
|
|
|
|
| RRSIG Type 16 validates the TXT - Result: 3|welcome
Validated: RRSIG-Owner www.silverbullets.co.uk., Algorithm: 8, 4 Labels, original TTL: 3600 sec, Signature-expiration: 30.09.2022, 10:33:40 +, Signature-Inception: 31.08.2022, 10:33:40 +, KeyTag 7980, Signer-Name: silverbullets.co.uk
|
|
|
|
|
| CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "p31e62v390tsb1ilb0rerhvgudngb87v" equal the hashed NSEC3-owner "p31e62v390tsb1ilb0rerhvgudngb87v" and the hashed NextOwner "0aj6j48hsui9pndctkkc7qumm41jpajt". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, TXT, RRSIG Validated: RRSIG-Owner p31e62v390tsb1ilb0rerhvgudngb87v.silverbullets.co.uk., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 30.09.2022, 10:33:40 +, Signature-Inception: 31.08.2022, 10:33:40 +, KeyTag 7980, Signer-Name: silverbullets.co.uk
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| AAAA-Query sends a valid NSEC3 RR as result with the hashed query name "p31e62v390tsb1ilb0rerhvgudngb87v" equal the hashed NSEC3-owner "p31e62v390tsb1ilb0rerhvgudngb87v" and the hashed NextOwner "0aj6j48hsui9pndctkkc7qumm41jpajt". So the zone confirmes the not-existence of that AAAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, TXT, RRSIG Validated: RRSIG-Owner p31e62v390tsb1ilb0rerhvgudngb87v.silverbullets.co.uk., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 30.09.2022, 10:33:40 +, Signature-Inception: 31.08.2022, 10:33:40 +, KeyTag 7980, Signer-Name: silverbullets.co.uk
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TLSA-Query (_443._tcp.www.silverbullets.co.uk) sends a valid NSEC3 RR as result with the hashed owner name "p31e62v390tsb1ilb0rerhvgudngb87v" (unhashed: www.silverbullets.co.uk). So that's the Closest Encloser of the query name.
Bitmap: A, TXT, RRSIG Validated: RRSIG-Owner p31e62v390tsb1ilb0rerhvgudngb87v.silverbullets.co.uk., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 30.09.2022, 10:33:40 +, Signature-Inception: 31.08.2022, 10:33:40 +, KeyTag 7980, Signer-Name: silverbullets.co.uk
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Next Closer Name "f8ctsv3v980pcjv2snlgkntil1v0ge8n" (unhashed: _tcp.www.silverbullets.co.uk) with the owner "b3u7fg015kohn2hl60v32r0mf44083eq" and the NextOwner "gf4jn3v7c55efm8u7968d93hknak8hjk". So that NSEC3 confirms the not-existence of the Next Closer Name. TLSA-Query (_443._tcp.www.silverbullets.co.uk) sends a valid NSEC3 RR as result with the hashed query name "eifhgjfn8a1o3mmd7v8oreqkt8a97819" between the hashed NSEC3-owner "b3u7fg015kohn2hl60v32r0mf44083eq" and the hashed NextOwner "gf4jn3v7c55efm8u7968d93hknak8hjk". So the zone confirmes the not-existence of that TLSA RR.
Bitmap: A, RRSIG Validated: RRSIG-Owner b3u7fg015kohn2hl60v32r0mf44083eq.silverbullets.co.uk., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 30.09.2022, 10:33:40 +, Signature-Inception: 31.08.2022, 10:33:40 +, KeyTag 7980, Signer-Name: silverbullets.co.uk
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Wildcard expansion of the ClosestEncloser "91plra6mbn7sdj4qost9mk4215n4b5fd" (unhashed: *.www.silverbullets.co.uk) with the owner "7d7i1kk0ffm96osfilkntg1ugeh0s4if" and the NextOwner "b3u7fg015kohn2hl60v32r0mf44083eq". So that NSEC3 confirms the not-existence of the Wildcard expansion.
Bitmap: CNAME, RRSIG Validated: RRSIG-Owner 7d7i1kk0ffm96osfilkntg1ugeh0s4if.silverbullets.co.uk., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 30.09.2022, 10:33:40 +, Signature-Inception: 31.08.2022, 10:33:40 +, KeyTag 7980, Signer-Name: silverbullets.co.uk
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| CAA-Query sends a valid NSEC3 RR as result with the hashed query name "p31e62v390tsb1ilb0rerhvgudngb87v" equal the hashed NSEC3-owner "p31e62v390tsb1ilb0rerhvgudngb87v" and the hashed NextOwner "0aj6j48hsui9pndctkkc7qumm41jpajt". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, TXT, RRSIG Validated: RRSIG-Owner p31e62v390tsb1ilb0rerhvgudngb87v.silverbullets.co.uk., Algorithm: 8, 4 Labels, original TTL: 60 sec, Signature-expiration: 30.09.2022, 10:33:40 +, Signature-Inception: 31.08.2022, 10:33:40 +, KeyTag 7980, Signer-Name: silverbullets.co.uk
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|