Zone (*) DNSSEC - Informations Zone : (root)(root) 1 DS RR published • Status: Valid because published2 DNSKEY RR found Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 8, KeyTag 59944, Flags 256
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 31.08.2019, 00:00:00 +, Signature-Inception: 10.08.2019, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : comcom 1 DS RR in the parent zone found 1 RRSIG RR to validate DS RR found RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 31.08.2019, 05:00:00 +, Signature-Inception: 18.08.2019, 04:00:00 +, KeyTag 59944, Signer-Name: (root)
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 59944 used to validate the DS RRSet in the parent zone2 DNSKEY RR found Public Key with Algorithm 8, KeyTag 17708, Flags 256
Public Key with Algorithm 8, KeyTag 30909, Flags 257 (SEP = Secure Entry Point)
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 25.08.2019, 18:25:33 +, Signature-Inception: 10.08.2019, 18:20:33 +, KeyTag 30909, Signer-Name: com
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 30909 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 30909, DigestType 2 and Digest "4tPJFvbe6scylOgmj7WIUESoM/xUWViPSpGEz8QaV2Y=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : thetradinghall.comthetradinghall.com 0 DS RR in the parent zone found DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "5a4ja9lv2nbi55m0pk9cbbd54iearn7q" between the hashed NSEC3-owner "5a4ilaroin5aevocseba9ajd0m9e0ojg" and the hashed NextOwner "5a4lo9b29sd492h63fsq9rh6fi1p54bp". So the parent zone confirmes the not-existence of a DS RR.Bitmap: NS, DS, RRSIG Validated: RRSIG-Owner 5a4ilaroin5aevocseba9ajd0m9e0ojg.com., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 23.08.2019, 04:23:12 +, Signature-Inception: 16.08.2019, 03:13:12 +, KeyTag 17708, Signer-Name: com
1 DNSKEY RR found Public Key with Algorithm 13, KeyTag 25176, Flags 256
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner thetradinghall.com., Algorithm: 13, 2 Labels, original TTL: 10800 sec, Signature-expiration: 29.08.2019, 00:00:00 +, Signature-Inception: 08.08.2019, 00:00:00 +, KeyTag 25176, Signer-Name: thetradinghall.com
• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 25176 used to validate the DNSKEY RRSetError: DNSKEY 25176 signs DNSKEY RRset, but no confirming DS RR in the parent zone found. No chain of trust created. RRSIG Type 1 validates the A - Result: 83.166.144.177 Validated: RRSIG-Owner thetradinghall.com., Algorithm: 13, 2 Labels, original TTL: 10800 sec, Signature-expiration: 29.08.2019, 00:00:00 +, Signature-Inception: 08.08.2019, 00:00:00 +, KeyTag 25176, Signer-Name: thetradinghall.com
RRSIG Type 28 validates the AAAA - Result: 2001:1600:0004:0008:F816:3EFF:FE2E:4F73 Validated: RRSIG-Owner thetradinghall.com., Algorithm: 13, 2 Labels, original TTL: 1800 sec, Signature-expiration: 29.08.2019, 00:00:00 +, Signature-Inception: 08.08.2019, 00:00:00 +, KeyTag 25176, Signer-Name: thetradinghall.com
RRSIG Type 50, expiration 2019-08-29 00:00:00 + validates the NSEC3 RR that proves the not-existence of the CNAME RR. Bitmap: A, NS, SOA, AAAA, RRSIG, DNSKEY, NSEC3PARAM, CDS
RRSIG Type 50, expiration 2019-08-29 00:00:00 + validates the NSEC3 RR that proves the not-existence of the TXT RR. Bitmap: A, NS, SOA, AAAA, RRSIG, DNSKEY, NSEC3PARAM, CDS
RRSIG Type 50, expiration 2019-08-29 00:00:00 + validates the NSEC3 RR that proves the not-existence of the TLSA RR. Bitmap: A, NS, SOA, AAAA, RRSIG, DNSKEY, NSEC3PARAM, CDS
RRSIG Type 50, expiration 2019-08-29 00:00:00 + validates the NSEC3 RR that proves the not-existence of the CAA RR. Bitmap: A, NS, SOA, AAAA, RRSIG, DNSKEY, NSEC3PARAM, CDS
Zone : www.thetradinghall.comwww.thetradinghall.com 0 DS RR in the parent zone found DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "fubhkk07ut96dgput2befpkuqd9sdjqv" between the hashed NSEC3-owner "fubhkk07ut96dgput2befpkuqd9sdjqu" and the hashed NextOwner "fubhkk07ut96dgput2befpkuqd9sdjr0". So the parent zone confirmes the not-existence of a DS RR.Bitmap: No Bitmap? Validated: RRSIG-Owner fubhkk07ut96dgput2befpkuqd9sdjqu.thetradinghall.com., Algorithm: 13, 3 Labels, original TTL: 10800 sec, Signature-expiration: 29.08.2019, 00:00:00 +, Signature-Inception: 08.08.2019, 00:00:00 +, KeyTag 25176, Signer-Name: thetradinghall.com