. to ci: No valid RRSIGs made by a key corresponding to a DS RR were found covering the DNSKEY RRset, resulting in no secure entry point (SEP) into the zone. See RFC 4035, Sec. 2.2, RFC 6840, Sec. 5.11. (196.49.0.84, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_512_D_KN)
. to ci: The DS RRset for the zone included algorithm 8 (RSASHA256), but no DS RR matched a DNSKEY with algorithm 8 that signs the zone's DNSKEY RRset. See RFC 4035, Sec. 2.2, RFC 6840, Sec. 5.11. (196.49.0.84, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_512_D_KN)
ci zone: The server(s) were not responsive to queries over TCP. See RFC 1035, Sec. 4.2. (2001:468:d01:20::80df:2023)
ci/DNSKEY (alg 8, id 36075): The DNSKEY RR was not found in the DNSKEY RRset returned by one or more servers. (196.49.0.84, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_512_D_KN)
ci/DNSKEY (alg 8, id 60224): The DNSKEY RR was not found in the DNSKEY RRset returned by one or more servers. (196.49.0.84, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_512_D_KN)
ci/NS: No RRSIG covering the RRset was returned in the response. See RFC 4035, Sec. 3.1.1. (196.49.0.84, UDP_-_EDNS0_4096_D_KN)
ci/SOA: No RRSIG covering the RRset was returned in the response. See RFC 4035, Sec. 3.1.1. (196.49.0.84, TCP_-_EDNS0_4096_D_N, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_4096_D_KN_0x20)
ci/SOA: No response was received from the server over TCP (tried 3 times). See RFC 1035, Sec. 4.2. (2001:468:d01:20::80df:2023, TCP_-_EDNS0_4096_D_N)
ci/CNAME has errors; select the "Denial of existence" DNSSEC option to see them.
d0968p7xq3.ci/A has errors; select the "Denial of existence" DNSSEC option to see them.
ci/NSEC3PARAM has errors; select the "Denial of existence" DNSSEC option to see them.
ci/DNSKEY has errors; select the "Denial of existence" DNSSEC option to see them.