mwfnijz9ph.dublin.lol/A has errors; select the "Denial of existence" DNSSEC option to see them.
dublin.lol/CNAME has errors; select the "Denial of existence" DNSSEC option to see them.
dublin.lol/TXT has errors; select the "Denial of existence" DNSSEC option to see them.
dublin.lol/MX has errors; select the "Denial of existence" DNSSEC option to see them.
dublin.lol/A has errors; select the "Denial of existence" DNSSEC option to see them.
dublin.lol/AAAA has errors; select the "Denial of existence" DNSSEC option to see them.
Warnings (20)
RRSIG dublin.lol/DS alg 5, id 26860: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 5 (RSASHA1). See RFC 8624, Sec. 3.1.
RRSIG lol/DNSKEY alg 5, id 54097: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 5 (RSASHA1). See RFC 8624, Sec. 3.1.
RRSIG lol/DNSKEY alg 5, id 54097: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 5 (RSASHA1). See RFC 8624, Sec. 3.1.
dublin.lol/DS (alg 13, id 42325): The server appears to support DNS cookies but did not return a COOKIE option. See RFC 7873, Sec. 5.2.3. (2001:67c:13cc::1:146, UDP_-_EDNS0_4096_D_KN)
dublin.lol/DS (alg 13, id 42325): The server appears to support DNS cookies but did not return a COOKIE option. See RFC 7873, Sec. 5.2.3. (2001:67c:13cc::1:146, UDP_-_EDNS0_4096_D_KN)
lol to dublin.lol: The following NS name(s) were found in the delegation NS RRset (i.e., in the lol zone), but not in the authoritative NS RRset: ns6.gandi.net See RFC 1034, Sec. 4.2.2.
lol/DNSKEY (alg 5, id 26860): The server appears to support DNS cookies but did not return a COOKIE option. See RFC 7873, Sec. 5.2.3. (194.169.218.146, 2001:67c:13cc::1:146, UDP_-_EDNS0_4096_D_KN)
lol/DNSKEY (alg 5, id 54097): The server appears to support DNS cookies but did not return a COOKIE option. See RFC 7873, Sec. 5.2.3. (194.169.218.146, 2001:67c:13cc::1:146, UDP_-_EDNS0_4096_D_KN)
lol/DNSKEY: The server appears to support DNS cookies but did not return a COOKIE option. See RFC 7873, Sec. 5.2.3. (194.169.218.146, UDP_-_EDNS0_512_D_KN)
lol/DS (alg 5, id 54097): DNSSEC implementers are prohibited from implementing signing with DS algorithm 1 (SHA-1). See RFC 8624, Sec. 3.2.
lol/DS (alg 5, id 54097): DNSSEC implementers are prohibited from implementing signing with DS algorithm 1 (SHA-1). See RFC 8624, Sec. 3.2.
lol/DS (alg 5, id 54097): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset. See RFC 4509, Sec. 3.
lol/DS (alg 5, id 54097): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset. See RFC 4509, Sec. 3.
mwfnijz9ph.dublin.lol/A has warnings; select the "Denial of existence" DNSSEC option to see them.
dublin.lol/CNAME has warnings; select the "Denial of existence" DNSSEC option to see them.
dublin.lol/TXT has warnings; select the "Denial of existence" DNSSEC option to see them.
dublin.lol/DS has warnings; select the "Denial of existence" DNSSEC option to see them.
dublin.lol/MX has warnings; select the "Denial of existence" DNSSEC option to see them.
dublin.lol/A has warnings; select the "Denial of existence" DNSSEC option to see them.
dublin.lol/AAAA has warnings; select the "Denial of existence" DNSSEC option to see them.