View on GitHub

DNSViz: A DNS visualization tool

opendnssec.org

DNSSEC options (hide)
  1. |?|
  2. |?|
  3. |?|
  4. |?|
  5. |?|
  6. |?|
  7. |?|
Notices
DNSSEC Authentication Chain

RRset statusRRset status

Bogus (4)
  • opendnssec.org/MX
  • opendnssec.org/NS
  • opendnssec.org/SOA
  • opendnssec.org/TXT

DNSKEY/DS/NSEC statusDNSKEY/DS/NSEC status

Bogus (2)
  • opendnssec.org/DNSKEY (alg 8, id 28926)
  • opendnssec.org/DNSKEY (alg 8, id 59395)
Secure (8)
  • ./DNSKEY (alg 8, id 16665)
  • ./DNSKEY (alg 8, id 19036)
  • opendnssec.org/DS (alg 8, id 59395)
  • org/DNSKEY (alg 7, id 21366)
  • org/DNSKEY (alg 7, id 33660)
  • org/DNSKEY (alg 7, id 53348)
  • org/DNSKEY (alg 7, id 9795)
  • org/DS (alg 7, id 21366)

Delegation statusDelegation status

Bogus (1)
  • org to opendnssec.org
Secure (1)
  • . to org

NoticesNotices

Errors (3)
  • RRSIG opendnssec.org/DNSKEY alg 8, id 59395: The Signature Expiration field of the RRSIG RR (2015-01-25 20:00:28+00:00) is 12 hours, 2 minutes in the past.
  • RRSIG opendnssec.org/DNSKEY alg 8, id 59395: The Signature Expiration field of the RRSIG RR (2015-01-25 20:00:28+00:00) is 12 hours, 2 minutes in the past.
  • org to opendnssec.org: No valid RRSIGs made by a key corresponding to a DS RR were found covering the DNSKEY RRset, resulting in no secure entry point (SEP) into the zone. (91.123.201.115, 91.206.174.4, 192.36.115.53, 2001:67c:394:15::4, 2a00:16d8:2:300:216:3cff:fea1:8ed5, 2a01:298:4::53, UDP_0_EDNS0_32768_4096)

DNSKEY legend

Full legend
SEP bit setSEP bit set
Revoke bit setRevoke bit set
Trust anchorTrust anchor
Download: png | svg
Warning JavaScript is required to make the graph below interactive.
DNSSEC authentication graph