View on GitHub

DNSViz: A DNS visualization tool

www.yadifa.eu

DNSSEC options (hide)
  1. |?|
  2. |?|
  3. |?|
  4. |?|
  5. |?|
  6. |?|
  7. |?|
Notices
DNSSEC Authentication Chain

RRset statusRRset status

Bogus (3)
  • lu.yadifa.eu/A
  • lu.yadifa.eu/AAAA
  • www.yadifa.eu/CNAME

DNSKEY/DS/NSEC statusDNSKEY/DS/NSEC status

Secure (10)
  • ./DNSKEY (alg 8, id 19036)
  • ./DNSKEY (alg 8, id 46551)
  • ./DNSKEY (alg 8, id 60615)
  • eu/DNSKEY (alg 8, id 2439)
  • eu/DNSKEY (alg 8, id 59479)
  • eu/DS (alg 8, id 59479)
  • yadifa.eu/DNSKEY (alg 7, id 34254)
  • yadifa.eu/DNSKEY (alg 8, id 303)
  • yadifa.eu/DNSKEY (alg 8, id 31555)
  • yadifa.eu/DS (alg 8, id 31555)

Delegation statusDelegation status

Secure (2)
  • . to eu
  • eu to yadifa.eu

NoticesNotices

Errors (11)
  • RRSIG lu.yadifa.eu/A alg 7, id 34254: The Signature Expiration field of the RRSIG RR (2016-06-27 00:45:51+00:00) is 58 seconds in the past.
  • RRSIG lu.yadifa.eu/A alg 8, id 303: The Signature Expiration field of the RRSIG RR (2016-06-27 00:45:51+00:00) is 58 seconds in the past.
  • RRSIG lu.yadifa.eu/AAAA alg 7, id 34254: The Signature Expiration field of the RRSIG RR (2016-06-27 00:45:51+00:00) is 58 seconds in the past.
  • RRSIG lu.yadifa.eu/AAAA alg 8, id 303: The Signature Expiration field of the RRSIG RR (2016-06-27 00:45:51+00:00) is 58 seconds in the past.
  • RRSIG www.yadifa.eu/CNAME alg 7, id 34254: The Signature Expiration field of the RRSIG RR (2016-06-27 00:45:51+00:00) is 57 seconds in the past.
  • RRSIG www.yadifa.eu/CNAME alg 7, id 34254: The Signature Expiration field of the RRSIG RR (2016-06-27 00:45:51+00:00) is 57 seconds in the past.
  • RRSIG www.yadifa.eu/CNAME alg 8, id 303: The Signature Expiration field of the RRSIG RR (2016-06-27 00:45:51+00:00) is 57 seconds in the past.
  • RRSIG www.yadifa.eu/CNAME alg 8, id 303: The Signature Expiration field of the RRSIG RR (2016-06-27 00:45:51+00:00) is 57 seconds in the past.
  • yadifa.eu/DNSKEY (alg 7, id 34254): The DNSKEY RRset for the zone included algorithm 7 (RSASHA1NSEC3SHA1), but no RRSIG with algorithm 7 covering the RRset was returned in the response. (185.36.4.252, 185.36.4.253, 185.36.6.252, 185.36.6.253, 2001:67c:40:3937::252, 2001:67c:40:3937::253, 2001:67c:9c:3937::252, 2001:67c:9c:3937::253, UDP_0_EDNS0_32768_4096)
  • yadifa.eu/DNSKEY (alg 8, id 303): The DNSKEY RRset for the zone included algorithm 7 (RSASHA1NSEC3SHA1), but no RRSIG with algorithm 7 covering the RRset was returned in the response. (185.36.4.252, 185.36.4.253, 185.36.6.252, 185.36.6.253, 2001:67c:40:3937::252, 2001:67c:40:3937::253, 2001:67c:9c:3937::252, 2001:67c:9c:3937::253, UDP_0_EDNS0_32768_4096)
  • yadifa.eu/DNSKEY (alg 8, id 31555): The DNSKEY RRset for the zone included algorithm 7 (RSASHA1NSEC3SHA1), but no RRSIG with algorithm 7 covering the RRset was returned in the response. (185.36.4.252, 185.36.4.253, 185.36.6.252, 185.36.6.253, 2001:67c:40:3937::252, 2001:67c:40:3937::253, 2001:67c:9c:3937::252, 2001:67c:9c:3937::253, UDP_0_EDNS0_32768_4096)

DNSKEY legend

Full legend
SEP bit setSEP bit set
Revoke bit setRevoke bit set
Trust anchorTrust anchor
Download: png | svg
Warning JavaScript is required to make the graph below interactive.
DNSSEC authentication graph