dds.mil/DNSKEY: The server responded with no OPT record, rather than with RCODE FORMERR. See RFC 6891, Sec. 7. (205.251.192.41, 205.251.194.143, 205.251.196.181, 205.251.199.64, 2600:9000:5300:2900::1, 2600:9000:5302:8f00::1, 2600:9000:5304:b500::1, 2600:9000:5307:4000::1, UDP_-_EDNS0_512_D_KN)
dds.mil/DS (alg 13, id 59866): DNSSEC implementers are prohibited from implementing signing with DS algorithm 1 (SHA-1). See RFC 8624, Sec. 3.2.
dds.mil/DS (alg 13, id 59866): DNSSEC implementers are prohibited from implementing signing with DS algorithm 1 (SHA-1). See RFC 8624, Sec. 3.2.
dds.mil/DS (alg 13, id 59866): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset. See RFC 4509, Sec. 3.
dds.mil/DS (alg 13, id 59866): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset. See RFC 4509, Sec. 3.
dds.mil/DNSKEY has warnings; select the "Denial of existence" DNSSEC option to see them.