| Zone (*) | DNSSEC - Informations |
|---|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 4 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 21831, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 38696, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 54393, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 22.04.2026, 00:00:00 +, Signature-Inception: 01.04.2026, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: io
|
|
io
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 57355, DigestType 2 and Digest laV8O6t4SdvN33xyracaiBRrFBEQMYylvmcgV+hlw+I=
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner io., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 22.04.2026, 05:00:00 +, Signature-Inception: 09.04.2026, 04:00:00 +, KeyTag 54393, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 54393 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 3 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 14541, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 57355, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 62718, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner io., Algorithm: 8, 1 Labels, original TTL: 3600 sec, Signature-expiration: 30.04.2026, 15:42:45 +, Signature-Inception: 09.04.2026, 14:42:45 +, KeyTag 57355, Signer-Name: io
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 57355 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 57355, DigestType 2 and Digest "laV8O6t4SdvN33xyracaiBRrFBEQMYylvmcgV+hlw+I=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: dedyn.io
|
|
dedyn.io
| 2 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 13, KeyTag 35233, DigestType 2 and Digest nGcq4ySIT5oBdDMMp2RPaWAXLB2UAj+Ub3B2Ob5tOrA=
|
|
|
|
|
| DS with Algorithm 13, KeyTag 35233, DigestType 4 and Digest zoB+diKdZKrohrJzI1W91o4snRA5YJCF3+FZM/4DHHGYGn+nf0WyIZL3ZySpsp+5
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner dedyn.io., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 30.04.2026, 15:42:45 +, Signature-Inception: 09.04.2026, 14:42:45 +, KeyTag 62718, Signer-Name: io
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 62718 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 1 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 13, KeyTag 35233, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner dedyn.io., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 23.04.2026, 00:00:00 +, Signature-Inception: 02.04.2026, 00:00:00 +, KeyTag 35233, Signer-Name: dedyn.io
|
|
|
|
|
| • Status: Good - Algorithmus 13 and DNSKEY with KeyTag 35233 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 35233, DigestType 2 and Digest "nGcq4ySIT5oBdDMMp2RPaWAXLB2UAj+Ub3B2Ob5tOrA=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 35233, DigestType 4 and Digest "zoB+diKdZKrohrJzI1W91o4snRA5YJCF3+FZM/4DHHGYGn+nf0WyIZL3ZySpsp+5" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: snakeoil.dedyn.io
|
|
snakeoil.dedyn.io
| 2 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 13, KeyTag 38222, DigestType 2 and Digest IvfAqcNQVt3k8z5DpHBqT1Um9qL7SjyU0OVSoy9Ryaw=
|
|
|
|
|
| DS with Algorithm 13, KeyTag 38222, DigestType 4 and Digest ocFC3Nt01l37FpJDpH3P3k8PTaErD7S1exKYbJlecLoEhcLe8W/eSLsIAjNrZAVM
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner snakeoil.dedyn.io., Algorithm: 13, 3 Labels, original TTL: 300 sec, Signature-expiration: 23.04.2026, 00:00:00 +, Signature-Inception: 02.04.2026, 00:00:00 +, KeyTag 35233, Signer-Name: dedyn.io
|
|
|
|
|
| • Status: Good - Algorithmus 13 and DNSKEY with KeyTag 35233 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 1 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 13, KeyTag 38222, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner snakeoil.dedyn.io., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 23.04.2026, 00:00:00 +, Signature-Inception: 02.04.2026, 00:00:00 +, KeyTag 38222, Signer-Name: snakeoil.dedyn.io
|
|
|
|
|
| • Status: Good - Algorithmus 13 and DNSKEY with KeyTag 38222 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 38222, DigestType 2 and Digest "IvfAqcNQVt3k8z5DpHBqT1Um9qL7SjyU0OVSoy9Ryaw=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 38222, DigestType 4 and Digest "ocFC3Nt01l37FpJDpH3P3k8PTaErD7S1exKYbJlecLoEhcLe8W/eSLsIAjNrZAVM" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| RRSIG Type 1 validates the A - Result: 73.164.216.153
Validated: RRSIG-Owner snakeoil.dedyn.io., Algorithm: 13, 3 Labels, original TTL: 60 sec, Signature-expiration: 23.04.2026, 00:00:00 +, Signature-Inception: 02.04.2026, 00:00:00 +, KeyTag 38222, Signer-Name: snakeoil.dedyn.io
|
|
|
|
|
| RRSIG Type 16 validates the TXT - Result: Just a test TXT record!
v=spf1 include:_spf.porkbun.com ~all
Validated: RRSIG-Owner snakeoil.dedyn.io., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 23.04.2026, 00:00:00 +, Signature-Inception: 02.04.2026, 00:00:00 +, KeyTag 38222, Signer-Name: snakeoil.dedyn.io
|
|
|
|
|
| RRSIG Type 257 validates the CAA - Result: 32773|issueletsencrypt.org;validationmethods=http-01;accounturi=https://acme-staging-v02.api.letsencrypt.org/acme/acct/188569844
32773|issueletsencrypt.org;validationmethods=http-01;accounturi=https://acme-v02.api.letsencrypt.org/acme/acct/2270421646
32777|issuewild;
Validated: RRSIG-Owner snakeoil.dedyn.io., Algorithm: 13, 3 Labels, original TTL: 3600 sec, Signature-expiration: 23.04.2026, 00:00:00 +, Signature-Inception: 02.04.2026, 00:00:00 +, KeyTag 38222, Signer-Name: snakeoil.dedyn.io
|
|
|
|
|
| CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "v3gdlm18dju2rsmim1a9qsr603mjqkjn" equal the hashed NSEC3-owner "v3gdlm18dju2rsmim1a9qsr603mjqkjn" and the hashed NextOwner "5l6quepiqj7mo2s5gi7ga25dajp86vm6". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, PTR, TXT, RRSIG, DNSKEY, NSEC3PARAM, CDS, CDNSKEY, CAA Validated: RRSIG-Owner v3gdlm18dju2rsmim1a9qsr603mjqkjn.snakeoil.dedyn.io., Algorithm: 13, 4 Labels, original TTL: 300 sec, Signature-expiration: 23.04.2026, 00:00:00 +, Signature-Inception: 02.04.2026, 00:00:00 +, KeyTag 38222, Signer-Name: snakeoil.dedyn.io
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| AAAA-Query sends a valid NSEC3 RR as result with the hashed query name "v3gdlm18dju2rsmim1a9qsr603mjqkjn" equal the hashed NSEC3-owner "v3gdlm18dju2rsmim1a9qsr603mjqkjn" and the hashed NextOwner "5l6quepiqj7mo2s5gi7ga25dajp86vm6". So the zone confirmes the not-existence of that AAAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, NS, SOA, PTR, TXT, RRSIG, DNSKEY, NSEC3PARAM, CDS, CDNSKEY, CAA Validated: RRSIG-Owner v3gdlm18dju2rsmim1a9qsr603mjqkjn.snakeoil.dedyn.io., Algorithm: 13, 4 Labels, original TTL: 300 sec, Signature-expiration: 23.04.2026, 00:00:00 +, Signature-Inception: 02.04.2026, 00:00:00 +, KeyTag 38222, Signer-Name: snakeoil.dedyn.io
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TLSA-Query (_443._tcp.snakeoil.dedyn.io) sends a valid NSEC3 RR as result with the hashed owner name "v3gdlm18dju2rsmim1a9qsr603mjqkjn" (unhashed: snakeoil.dedyn.io). So that's the Closest Encloser of the query name.
Bitmap: A, NS, SOA, PTR, TXT, RRSIG, DNSKEY, NSEC3PARAM, CDS, CDNSKEY, CAA Validated: RRSIG-Owner v3gdlm18dju2rsmim1a9qsr603mjqkjn.snakeoil.dedyn.io., Algorithm: 13, 4 Labels, original TTL: 300 sec, Signature-expiration: 23.04.2026, 00:00:00 +, Signature-Inception: 02.04.2026, 00:00:00 +, KeyTag 38222, Signer-Name: snakeoil.dedyn.io
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Next Closer Name "ddk7q3bpmb48863om6qck6ea5evm21hq" (unhashed: _tcp.snakeoil.dedyn.io) with the owner "8ff0rne9o3tapqq8uaaeehr323onjl0j" and the NextOwner "ghvmqiuomsimef016g5c4sgciut62q0q". So that NSEC3 confirms the not-existence of the Next Closer Name. TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Wildcard expansion of the ClosestEncloser "9t4obkac9mji9c60vgl4qn1a725r41oc" (unhashed: *.snakeoil.dedyn.io) with the owner "8ff0rne9o3tapqq8uaaeehr323onjl0j" and the NextOwner "ghvmqiuomsimef016g5c4sgciut62q0q". So that NSEC3 confirms the not-existence of the Wildcard expansion.
Bitmap: No Bitmap? Validated: RRSIG-Owner 8ff0rne9o3tapqq8uaaeehr323onjl0j.snakeoil.dedyn.io., Algorithm: 13, 4 Labels, original TTL: 300 sec, Signature-expiration: 23.04.2026, 00:00:00 +, Signature-Inception: 02.04.2026, 00:00:00 +, KeyTag 38222, Signer-Name: snakeoil.dedyn.io
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
Zone: www.snakeoil.dedyn.io
|
|
www.snakeoil.dedyn.io
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone sends valid NSEC3 RR with the Hash "v3gdlm18dju2rsmim1a9qsr603mjqkjn" as Owner. That's the Hash of "snakeoil.dedyn.io" with the NextHashedOwnerName "5l6quepiqj7mo2s5gi7ga25dajp86vm6". So that domain name is the Closest Encloser of "www.snakeoil.dedyn.io". Opt-Out: False.
Bitmap: A, NS, SOA, PTR, TXT, RRSIG, DNSKEY, NSEC3PARAM, CDS, CDNSKEY, CAA Validated: RRSIG-Owner v3gdlm18dju2rsmim1a9qsr603mjqkjn.snakeoil.dedyn.io., Algorithm: 13, 4 Labels, original TTL: 300 sec, Signature-expiration: 23.04.2026, 00:00:00 +, Signature-Inception: 02.04.2026, 00:00:00 +, KeyTag 38222, Signer-Name: snakeoil.dedyn.io
|
|
|
|
|
| RRSIG Type 5 validates the CNAME - Result: snakeoil.dedyn.io
Validated: RRSIG-Owner www.snakeoil.dedyn.io., Algorithm: 13, 4 Labels, original TTL: 3600 sec, Signature-expiration: 23.04.2026, 00:00:00 +, Signature-Inception: 02.04.2026, 00:00:00 +, KeyTag 38222, Signer-Name: snakeoil.dedyn.io
|