army.mil/TXT: DNSSEC was effectively downgraded because the response had an invalid RCODE (SERVFAIL) with EDNS enabled. (192.82.113.7, UDP_-_NOEDNS_)
army.mil/TXT: The DNSSEC records necessary to validate the response could not be retrieved from the server. (192.82.113.7, UDP_-_EDNS0_4096_D_K)
army.mil/TXT: The response had an invalid RCODE (SERVFAIL) until EDNS was disabled (however, this server appeared to respond legitimately to other queries with EDNS enabled). (192.82.113.7, UDP_-_EDNS0_4096_D_K)
Warnings (8)
army.mil/DS (alg 8, id 30256): DNSSEC specification prohibits signing with DS records that use digest algorithm 1 (SHA-1).
army.mil/DS (alg 8, id 30256): DNSSEC specification prohibits signing with DS records that use digest algorithm 1 (SHA-1).
army.mil/DS (alg 8, id 30256): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset.
army.mil/DS (alg 8, id 30256): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset.
mil/DS (alg 8, id 51349): DNSSEC specification prohibits signing with DS records that use digest algorithm 1 (SHA-1).
mil/DS (alg 8, id 51349): DNSSEC specification prohibits signing with DS records that use digest algorithm 1 (SHA-1).
mil/DS (alg 8, id 51349): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset.
mil/DS (alg 8, id 51349): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset.