View on GitHub

DNSViz: A DNS visualization tool

mg

DNSSEC options (hide)
  1. |?|
  2. |?|
  3. |?|
  4. |?|
  5. |?|
  6. |?|
  7. |?|
Notices
DNSSEC Authentication Chain

RRset statusRRset status

Bogus (2)
  • mg/NS
  • mg/SOA

DNSKEY/DS/NSEC statusDNSKEY/DS/NSEC status

Bogus (3)
  • mg/DNSKEY (alg 5, id 32758)
  • mg/DNSKEY (alg 5, id 44863)
  • mg/DNSKEY (alg 5, id 64652)
Secure (4)
  • ./DNSKEY (alg 8, id 15768)
  • ./DNSKEY (alg 8, id 19036)
  • ./DNSKEY (alg 8, id 20326)
  • mg/DS (alg 5, id 64652)

Delegation statusDelegation status

Bogus (1)
  • . to mg

NoticesNotices

Errors (5)
  • . to mg: No valid RRSIGs made by a key corresponding to a DS RR were found covering the DNSKEY RRset, resulting in no secure entry point (SEP) into the zone. (87.98.132.231, 91.203.32.147, 196.192.32.2, 196.192.42.153, 199.19.5.24, 199.19.6.24, 2001:500:92::24, 2001:500:96::24, UDP_0_EDNS0_32768_4096)
  • RRSIG mg/DNSKEY alg 5, id 64652: The Signature Inception field of the RRSIG RR (2017-09-05 23:38:28+00:00) is 30 minutes in the future.
  • RRSIG mg/DNSKEY alg 5, id 64652: The Signature Inception field of the RRSIG RR (2017-09-05 23:38:28+00:00) is 30 minutes in the future.
  • RRSIG mg/DNSKEY alg 5, id 64652: The Signature Inception field of the RRSIG RR (2017-09-05 23:38:28+00:00) is 30 minutes in the future.
  • RRSIG mg/SOA alg 5, id 44863: The Signature Inception field of the RRSIG RR (2017-09-05 23:38:28+00:00) is 30 minutes in the future.

DNSKEY legend

Full legend
SEP bit setSEP bit set
Revoke bit setRevoke bit set
Trust anchorTrust anchor
Download: png | svg
Warning JavaScript is required to make the graph below interactive.
DNSSEC authentication graph