_25._tcp.mx1.trt1.jus.br/TLSA (NXDOMAIN): No NSEC RR(s) were returned to validate the NXDOMAIN response. See RFC 4035, Sec. 3.1.3.2, RFC 5155, Sec. 7.2.2. (201.33.31.68, UDP_-_EDNS0_4096_D_K)
_tcp.mx1.trt1.jus.br/NS (NXDOMAIN): No NSEC RR(s) were returned to validate the NXDOMAIN response. See RFC 4035, Sec. 3.1.3.2, RFC 5155, Sec. 7.2.2. (201.33.31.68, UDP_-_EDNS0_4096_D_K)
trt1.jus.br zone: The server(s) were not responsive to queries over UDP. See RFC 1035, Sec. 4.2. (177.38.99.133)
trt1.jus.br/DNSKEY: The response (485 bytes) was malformed. (201.33.31.68, UDP_-_EDNS0_512_D_K)
trt1.jus.br/SOA: No RRSIG covering the RRset was returned in the response. See RFC 4035, Sec. 3.1.1. (201.33.31.68, UDP_-_EDNS0_4096_D_K)
trt1.jus.br/CNAME has errors; select the "Denial of existence" DNSSEC option to see them.
Warnings (5)
RRSIG mx1.trt1.jus.br/A alg 7, id 3248: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1). See RFC 8624, Sec. 3.1.
RRSIG trt1.jus.br/DNSKEY alg 7, id 16125: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1). See RFC 8624, Sec. 3.1.
RRSIG trt1.jus.br/DNSKEY alg 7, id 16125: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1). See RFC 8624, Sec. 3.1.
RRSIG trt1.jus.br/DNSKEY alg 7, id 3248: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1). See RFC 8624, Sec. 3.1.
RRSIG trt1.jus.br/DNSKEY alg 7, id 3248: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1). See RFC 8624, Sec. 3.1.