| Zone (*) | DNSSEC - Informations |
|---|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 25266, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 22.05.2019, 00:00:00 +, Signature-Inception: 01.05.2019, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: com
|
|
com
| 1 DS RR in the parent zone found
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 19.05.2019, 21:00:00 +, Signature-Inception: 06.05.2019, 20:00:00 +, KeyTag 25266, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 25266 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 3800, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 30909, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 17.05.2019, 18:25:33 +, Signature-Inception: 02.05.2019, 18:20:33 +, KeyTag 30909, Signer-Name: com
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 30909 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 30909, DigestType 2 and Digest "4tPJFvbe6scylOgmj7WIUESoM/xUWViPSpGEz8QaV2Y=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: uneschewed.com
|
|
uneschewed.com
| 1 DS RR in the parent zone found
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner uneschewed.com., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 10.05.2019, 05:32:50 +, Signature-Inception: 03.05.2019, 04:22:50 +, KeyTag 3800, Signer-Name: com
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 3800 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 1 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 13, KeyTag 54395, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner uneschewed.com., Algorithm: 13, 2 Labels, original TTL: 86400 sec, Signature-expiration: 16.05.2019, 00:00:00 +, Signature-Inception: 25.04.2019, 00:00:00 +, KeyTag 54395, Signer-Name: uneschewed.com
|
|
|
|
|
| • Status: Good - Algorithmus 13 and DNSKEY with KeyTag 54395 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 54395, DigestType 2 and Digest "Y9YCnpkzISz8tqhO5JjEPct0WIiIlKSO5+u5JRoLoLk=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| RRSIG Type 1 validates the A - Result: 50.23.147.3
Validated: RRSIG-Owner uneschewed.com., Algorithm: 13, 2 Labels, original TTL: 300 sec, Signature-expiration: 16.05.2019, 00:00:00 +, Signature-Inception: 25.04.2019, 00:00:00 +, KeyTag 54395, Signer-Name: uneschewed.com
|
|
|
|
|
| RRSIG Type 16 validates the TXT - Result: MS=DD51222E3FEA405536032EF1EB29A86B48E2E8F1
Validated: RRSIG-Owner uneschewed.com., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 16.05.2019, 00:00:00 +, Signature-Inception: 25.04.2019, 00:00:00 +, KeyTag 54395, Signer-Name: uneschewed.com
|
|
|
|
|
| RRSIG Type 47, expiration 2019-05-16 00:00:00 + validates the NSEC RR that proves the not-existence of the CNAME RR. Owner uneschewed.com, NextOwner: *.uneschewed.com.
Bitmap: A, NS, SOA, MX, TXT, RRSIG, NSEC, DNSKEY
|
|
|
|
|
| RRSIG Type 47, expiration 2019-05-16 00:00:00 + validates the NSEC RR that proves the not-existence of the AAAA RR. Owner uneschewed.com, NextOwner: *.uneschewed.com.
Bitmap: A, NS, SOA, MX, TXT, RRSIG, NSEC, DNSKEY
|
|
|
|
|
| RRSIG Type 47, expiration 2019-05-16 00:00:00 + validates the NSEC RR that proves the not-existence of the TLSA RR. Owner *.uneschewed.com, NextOwner: 7b1b3efe7fa895be004106a70b981bc0.uneschewed.com.
Bitmap: A, RRSIG, NSEC
|
|
|
|
|
| RRSIG Type 47, expiration 2019-05-16 00:00:00 + validates the NSEC RR that proves the not-existence of the CAA RR. Owner uneschewed.com, NextOwner: *.uneschewed.com.
Bitmap: A, NS, SOA, MX, TXT, RRSIG, NSEC, DNSKEY
|
|
|
Zone: www.uneschewed.com
|
|
www.uneschewed.com
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone has a valid NSEC RR as result with the domain name between the NSEC-Owner "*.uneschewed.com" and the NextOwner "7b1b3efe7fa895be004106a70b981bc0.uneschewed.com". So the parent zone confirmes the non-existence of a DS RR.
Bitmap: A, RRSIG, NSEC
|
|
|
|
|
| DS-Query in the parent zone has a valid NSEC RR as result with the domain name between the NSEC-Owner "u3qoysblrc3z.uneschewed.com" and the NextOwner "uneschewed.com". So the parent zone confirmes the non-existence of a DS RR.
Bitmap: CNAME, RRSIG, NSEC
|
|
|
|
|
| RRSIG Type 1, expiration 2019-05-16 00:00:00 + doesn't validate the A - Result. Signature is invalid.
|
|
|
|
|
| RRSIG Type 47, expiration 2019-05-16 00:00:00 + validates the NSEC RR that proves the not-existence of the A RR. Owner *.uneschewed.com, NextOwner: 7b1b3efe7fa895be004106a70b981bc0.uneschewed.com.
Bitmap: A, RRSIG, NSEC
|
|
|
|
|
| RRSIG Type 47, expiration 2019-05-16 00:00:00 + validates the NSEC RR that proves the not-existence of the CNAME RR. Owner *.uneschewed.com, NextOwner: 7b1b3efe7fa895be004106a70b981bc0.uneschewed.com.
Bitmap: A, RRSIG, NSEC
|
|
|
|
|
| RRSIG Type 47, expiration 2019-05-16 00:00:00 + validates the NSEC RR that proves the not-existence of the TXT RR. Owner *.uneschewed.com, NextOwner: 7b1b3efe7fa895be004106a70b981bc0.uneschewed.com.
Bitmap: A, RRSIG, NSEC
|
|
|
|
|
| RRSIG Type 47, expiration 2019-05-16 00:00:00 + validates the NSEC RR that proves the not-existence of the AAAA RR. Owner *.uneschewed.com, NextOwner: 7b1b3efe7fa895be004106a70b981bc0.uneschewed.com.
Bitmap: A, RRSIG, NSEC
|
|
|
|
|
| RRSIG Type 47, expiration 2019-05-16 00:00:00 + validates the NSEC RR that proves the not-existence of the TLSA RR. Owner *.uneschewed.com, NextOwner: 7b1b3efe7fa895be004106a70b981bc0.uneschewed.com.
Bitmap: A, RRSIG, NSEC
|
|
|
|
|
| RRSIG Type 47, expiration 2019-05-16 00:00:00 + validates the NSEC RR that proves the not-existence of the CAA RR. Owner *.uneschewed.com, NextOwner: 7b1b3efe7fa895be004106a70b981bc0.uneschewed.com.
Bitmap: A, RRSIG, NSEC
|