View on GitHub

DNSViz: A DNS visualization tool

202.5.185.in-addr.arpa

DNSSEC options (hide)
  1. |?|
  2. |?|
  3. |?|
  4. |?|
  5. |?|
  6. |?|
  7. |?|
  8. |?|
  9. |?|
  10. |?|
Notices
DNSSEC Authentication Chain

RRset statusRRset status

Bogus (5)
  • 202.5.185.in-addr.arpa/NS
  • 202.5.185.in-addr.arpa/NSEC3PARAM
  • 202.5.185.in-addr.arpa/NSEC3PARAM
  • 202.5.185.in-addr.arpa/SOA
  • 202.5.185.in-addr.arpa/SOA

DNSKEY/DS/NSEC statusDNSKEY/DS/NSEC status

Bogus (3)
  • 202.5.185.in-addr.arpa/DNSKEY (alg 14, id 37049)
  • 202.5.185.in-addr.arpa/DNSKEY (alg 14, id 50003)
  • 202.5.185.in-addr.arpa/DNSKEY (alg 14, id 6799)
Secure (18)
  • ./DNSKEY (alg 8, id 20038)
  • ./DNSKEY (alg 8, id 20326)
  • ./DNSKEY (alg 8, id 61050)
  • 185.in-addr.arpa/DNSKEY (alg 13, id 61572)
  • 185.in-addr.arpa/DS (alg 13, id 61572)
  • 202.5.185.in-addr.arpa/DS (alg 14, id 37049)
  • arpa/DNSKEY (alg 8, id 14488)
  • arpa/DNSKEY (alg 8, id 3673)
  • arpa/DNSKEY (alg 8, id 42581)
  • arpa/DS (alg 8, id 42581)
  • in-addr.arpa/DNSKEY (alg 8, id 25506)
  • in-addr.arpa/DNSKEY (alg 8, id 47054)
  • in-addr.arpa/DNSKEY (alg 8, id 54956)
  • in-addr.arpa/DNSKEY (alg 8, id 7420)
  • in-addr.arpa/DS (alg 8, id 47054)
  • in-addr.arpa/DS (alg 8, id 53696)
  • in-addr.arpa/DS (alg 8, id 54956)
  • in-addr.arpa/DS (alg 8, id 63982)
Non_existent (2)
  • in-addr.arpa/DNSKEY (alg 8, id 53696)
  • in-addr.arpa/DNSKEY (alg 8, id 63982)

Delegation statusDelegation status

Bogus (1)
  • 185.in-addr.arpa to 202.5.185.in-addr.arpa
Secure (3)
  • . to arpa
  • arpa to in-addr.arpa
  • in-addr.arpa to 185.in-addr.arpa

NoticesNotices

Errors (19)
  • 185.in-addr.arpa to 202.5.185.in-addr.arpa: No valid RRSIGs made by a key corresponding to a DS RR were found covering the DNSKEY RRset, resulting in no secure entry point (SEP) into the zone. See RFC 4035, Sec. 2.2, RFC 6840, Sec. 5.11. (54.93.203.146, 185.5.201.53, 185.5.202.53, 2a02:cdc5:9715:0:185:5:201:53, 2a02:cdc6:3100:0:185:5:202:53, 2a05:d014:499:9c00:582a:ca59:9fb0:4ee5, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_512_D_KN)
  • 185.in-addr.arpa to 202.5.185.in-addr.arpa: The DS RRset for the zone included algorithm 14 (ECDSAP384SHA384), but no DS RR matched a DNSKEY with algorithm 14 that signs the zone's DNSKEY RRset. See RFC 4035, Sec. 2.2, RFC 6840, Sec. 5.11. (185.5.201.53, 2a02:cdc5:9715:0:185:5:201:53, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_512_D_KN)
  • 202.5.185.in-addr.arpa/DNSKEY (alg 14, id 37049): The DNSKEY RR was not found in the DNSKEY RRset returned by one or more servers. (185.5.201.53, 2a02:cdc5:9715:0:185:5:201:53, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_512_D_KN)
  • RRSIG 202.5.185.in-addr.arpa/DNSKEY alg 14, id 37049: The Signature Expiration field of the RRSIG RR (2024-09-21 15:47:31+00:00) is 17 days in the past. See RFC 4035, Sec. 5.3.1.
  • RRSIG 202.5.185.in-addr.arpa/DNSKEY alg 14, id 37049: The Signature Expiration field of the RRSIG RR (2024-09-21 15:47:31+00:00) is 17 days in the past. See RFC 4035, Sec. 5.3.1.
  • RRSIG 202.5.185.in-addr.arpa/DNSKEY alg 14, id 37049: The Signature Expiration field of the RRSIG RR (2024-09-21 15:47:31+00:00) is 17 days in the past. See RFC 4035, Sec. 5.3.1.
  • RRSIG 202.5.185.in-addr.arpa/DNSKEY alg 14, id 50003: The Signature Expiration field of the RRSIG RR (2024-09-21 15:47:31+00:00) is 17 days in the past. See RFC 4035, Sec. 5.3.1.
  • RRSIG 202.5.185.in-addr.arpa/DNSKEY alg 14, id 50003: The Signature Expiration field of the RRSIG RR (2024-09-21 15:47:31+00:00) is 17 days in the past. See RFC 4035, Sec. 5.3.1.
  • RRSIG 202.5.185.in-addr.arpa/DNSKEY alg 14, id 50003: The Signature Expiration field of the RRSIG RR (2024-09-21 15:47:31+00:00) is 17 days in the past. See RFC 4035, Sec. 5.3.1.
  • RRSIG 202.5.185.in-addr.arpa/NS alg 14, id 6799: The Signature Expiration field of the RRSIG RR (2024-09-25 12:28:09+00:00) is 13 days in the past. See RFC 4035, Sec. 5.3.1.
  • RRSIG 202.5.185.in-addr.arpa/NSEC3PARAM alg 14, id 6799: The Signature Expiration field of the RRSIG RR (2024-09-28 04:29:46+00:00) is 11 days in the past. See RFC 4035, Sec. 5.3.1.
  • RRSIG 202.5.185.in-addr.arpa/SOA alg 14, id 6799: The Signature Expiration field of the RRSIG RR (2024-09-28 19:21:23+00:00) is 10 days in the past. See RFC 4035, Sec. 5.3.1.
  • 202.5.185.in-addr.arpa/CNAME has errors; select the "Denial of existence" DNSSEC option to see them.
  • 202.5.185.in-addr.arpa/TXT has errors; select the "Denial of existence" DNSSEC option to see them.
  • 202.5.185.in-addr.arpa/MX has errors; select the "Denial of existence" DNSSEC option to see them.
  • 202.5.185.in-addr.arpa/CDS has errors; select the "Denial of existence" DNSSEC option to see them.
  • 2iztd.5017d.202.5.185.in-addr.arpa/A has errors; select the "Denial of existence" DNSSEC option to see them.
  • 202.5.185.in-addr.arpa/DNSKEY has errors; select the "Denial of existence" DNSSEC option to see them.
  • 202.5.185.in-addr.arpa/CDNSKEY has errors; select the "Denial of existence" DNSSEC option to see them.
Warnings (6)
  • 202.5.185.in-addr.arpa/CNAME has warnings; select the "Denial of existence" DNSSEC option to see them.
  • 202.5.185.in-addr.arpa/TXT has warnings; select the "Denial of existence" DNSSEC option to see them.
  • 202.5.185.in-addr.arpa/MX has warnings; select the "Denial of existence" DNSSEC option to see them.
  • 202.5.185.in-addr.arpa/CDS has warnings; select the "Denial of existence" DNSSEC option to see them.
  • 2iztd.5017d.202.5.185.in-addr.arpa/A has warnings; select the "Denial of existence" DNSSEC option to see them.
  • 202.5.185.in-addr.arpa/CDNSKEY has warnings; select the "Denial of existence" DNSSEC option to see them.

DNSKEY legend

Full legend
SEP bit setSEP bit set
Revoke bit setRevoke bit set
Trust anchorTrust anchor
Download: png | svg
Warning JavaScript is required to make the graph below interactive.
DNSSEC authentication graph