it to comunesbt.it: No valid RRSIGs made by a key corresponding to a DS RR were found covering the DNSKEY RRset, resulting in no secure entry point (SEP) into the zone. See RFC 4035, Sec. 2.2, RFC 6840, Sec. 5.11. (54.93.203.146, 185.5.201.53, 185.5.202.53, 2a02:cdc5:9715:0:185:5:201:53, 2a02:cdc6:3100:0:185:5:202:53, 2a05:d014:499:9c00:582a:ca59:9fb0:4ee5, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_512_D_KN)
it to comunesbt.it: The DS RRset for the zone included algorithm 14 (ECDSAP384SHA384), but no DS RR matched a DNSKEY with algorithm 14 that signs the zone's DNSKEY RRset. See RFC 4035, Sec. 2.2, RFC 6840, Sec. 5.11. (54.93.203.146, 185.5.201.53, 185.5.202.53, 2a02:cdc5:9715:0:185:5:201:53, 2a02:cdc6:3100:0:185:5:202:53, 2a05:d014:499:9c00:582a:ca59:9fb0:4ee5, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_512_D_KN)
Warnings (6)
RRSIG comunesbt.it/DS alg 10, id 18395: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 10 (RSASHA512). See RFC 8624, Sec. 3.1.
RRSIG it/DNSKEY alg 10, id 18395: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 10 (RSASHA512). See RFC 8624, Sec. 3.1.
RRSIG it/DNSKEY alg 10, id 18395: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 10 (RSASHA512). See RFC 8624, Sec. 3.1.
RRSIG it/DNSKEY alg 10, id 41901: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 10 (RSASHA512). See RFC 8624, Sec. 3.1.
RRSIG it/DNSKEY alg 10, id 41901: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 10 (RSASHA512). See RFC 8624, Sec. 3.1.
comunesbt.it/DS has warnings; select the "Denial of existence" DNSSEC option to see them.