View on GitHub

DNSViz: A DNS visualization tool

desguacebizkaia.com.es

Updated: 2020-03-25 12:57:52 UTC (1502 days ago) Update now
« Previous analysis | Next analysis »
DNSSEC options (hide)
  1. |?|
  2. |?|
  3. |?|
  4. |?|
  5. |?|
  6. |?|
  7. |?|
Notices
DNSSEC Authentication Chain

RRset statusRRset status

Insecure (3)
  • desguacebizkaia.com.es/A
  • desguacebizkaia.com.es/NS
  • desguacebizkaia.com.es/SOA
Secure (1)
  • com.es/SOA

DNSKEY/DS/NSEC statusDNSKEY/DS/NSEC status

Secure (15)
  • ./DNSKEY (alg 8, id 20326)
  • ./DNSKEY (alg 8, id 33853)
  • ./DNSKEY (alg 8, id 48903)
  • NSEC3 proving non-existence of desguacebizkaia.com.es/DS
  • com.es/DNSKEY (alg 8, id 29574)
  • com.es/DNSKEY (alg 8, id 34556)
  • com.es/DNSKEY (alg 8, id 8444)
  • com.es/DS (alg 8, id 34556)
  • com.es/DS (alg 8, id 34556)
  • com.es/DS (alg 8, id 6901)
  • es/DNSKEY (alg 8, id 15034)
  • es/DNSKEY (alg 8, id 29450)
  • es/DNSKEY (alg 8, id 50252)
  • es/DS (alg 8, id 29450)
  • es/DS (alg 8, id 29450)
Non_existent (1)
  • com.es/DNSKEY (alg 8, id 6901)

Delegation statusDelegation status

Insecure (1)
  • com.es to desguacebizkaia.com.es
Secure (2)
  • . to es
  • es to com.es

NoticesNotices

Errors (3)
  • desguacebizkaia.com.es zone: The server(s) were not responsive to queries over TCP. (216.21.226.71, 216.21.231.244, 216.21.232.159, 216.21.235.237, 216.21.236.176)
  • desguacebizkaia.com.es/SOA: No response was received from the server over TCP (tried 3 times). (216.21.226.71, 216.21.231.244, 216.21.232.159, 216.21.235.237, 216.21.236.176, TCP_-_EDNS0_4096_D)
  • desguacebizkaia.com.es/SOA: No response was received from the server over UDP (tried 12 times). (216.21.226.71, 216.21.231.244, 216.21.235.237, 216.21.236.176, UDP_-_NOEDNS_, UDP_-_NOEDNS__0x20)
Warnings (14)
  • com.es to desguacebizkaia.com.es: The following NS name(s) were found in the authoritative NS RRset, but not in the delegation NS RRset (i.e., in the com.es zone): dns159.b.register.com, dns237.c.register.com, dns244.a.register.com, dns176.d.register.com
  • com.es to desguacebizkaia.com.es: The following NS name(s) were found in the delegation NS RRset (i.e., in the com.es zone), but not in the authoritative NS RRset: dns1.register.com, dns2.register.com
  • com.es/DS (alg 8, id 34556): DNSSEC specification prohibits signing with DS records that use digest algorithm 1 (SHA-1).
  • com.es/DS (alg 8, id 34556): DNSSEC specification prohibits signing with DS records that use digest algorithm 1 (SHA-1).
  • com.es/DS (alg 8, id 34556): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset.
  • com.es/DS (alg 8, id 34556): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset.
  • com.es/DS (alg 8, id 6901): DNSSEC specification prohibits signing with DS records that use digest algorithm 1 (SHA-1).
  • com.es/DS (alg 8, id 6901): DNSSEC specification prohibits signing with DS records that use digest algorithm 1 (SHA-1).
  • com.es/DS (alg 8, id 6901): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset.
  • com.es/DS (alg 8, id 6901): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset.
  • es/DS (alg 8, id 29450): DNSSEC specification prohibits signing with DS records that use digest algorithm 1 (SHA-1).
  • es/DS (alg 8, id 29450): DNSSEC specification prohibits signing with DS records that use digest algorithm 1 (SHA-1).
  • es/DS (alg 8, id 29450): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset.
  • es/DS (alg 8, id 29450): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset.

DNSKEY legend

Full legend
SEP bit setSEP bit set
Revoke bit setRevoke bit set
Trust anchorTrust anchor
Download: png | svg
Warning JavaScript is required to make the graph below interactive.
DNSSEC authentication graph