Zone (*) DNSSEC - Informations (beta) (root) 1 DS RR published • Status: Valide because published3 DNSKEY RR found Public Key with Algorithm 8, KeyTag 16749, Flags 256 Public Key with Algorithm 8, KeyTag 19164, Flags 385 Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point) 2 RRSIG RR to validate DNSKEY RR found • Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 03.03.2019, 00:00:00, Signature-Inception: 10.02.2019, 00:00:00, KeyTag 19164, Signer-Name: (root)• Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 03.03.2019, 00:00:00, Signature-Inception: 10.02.2019, 00:00:00, KeyTag 20326, Signer-Name: (root)• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 19164 used to validate the DNSKEY RRSet• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet• Status: Valide Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneeu 1 DS RR in the parent zone found 1 RRSIG RR to validate DS RR found Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 24.02.2019, 05:00:00, Signature-Inception: 11.02.2019, 04:00:00, KeyTag 16749, Signer-Name: (root) • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 16749 used to validate the DS RRSet in the parent zone2 DNSKEY RR found Public Key with Algorithm 8, KeyTag 28188, Flags 256 Public Key with Algorithm 8, KeyTag 59479, Flags 257 (SEP = Secure Entry Point) 2 RRSIG RR to validate DNSKEY RR found • Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 16.02.2019, 01:07:21, Signature-Inception: 09.02.2019, 00:59:22, KeyTag 28188, Signer-Name: eu• Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 16.02.2019, 01:07:21, Signature-Inception: 09.02.2019, 00:59:22, KeyTag 59479, Signer-Name: eu• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 28188 used to validate the DNSKEY RRSet• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 59479 used to validate the DNSKEY RRSet• Status: Valide Chain of trust. Parent-DS with Algorithm 8, KeyTag 59479, DigestType 2 and Digest "XbqoG8C+/pIYhtjaKEmNn9RBtFf7DjZCoLL5gRyOFeA=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zonethebluemountain.eu 0 DS RR in the parent zone found DS-Query in the parent zone has a valide NSEC3 RR as result with the hashed domain name between the hashed NSEC3-owner and the hashed NextOwner. So the parent zone confirmes the non-existence of a DS RR. 0 DNSKEY RR found store.thebluemountain.eu 0 DS RR in the parent zone found 0 DNSKEY RR found www.store.thebluemountain.eu 0 DS RR in the parent zone found