View on GitHub

DNSViz: A DNS visualization tool

extra-six.tpddns.cn

Updated: 2020-03-25 18:25:13 UTC (1491 days ago) Update now
« Previous analysis | Next analysis »
DNSSEC options (hide)
  1. |?|
  2. |?|
  3. |?|
  4. |?|
  5. |?|
  6. |?|
  7. |?|
Notices
DNSSEC Authentication Chain

RRset statusRRset status

Insecure (1)
  • extra-six.tpddns.cn/A
Secure (3)
  • cn/SOA
  • cn/SOA
  • cn/SOA

DNSKEY/DS/NSEC statusDNSKEY/DS/NSEC status

Secure (7)
  • ./DNSKEY (alg 8, id 20326)
  • ./DNSKEY (alg 8, id 33853)
  • ./DNSKEY (alg 8, id 48903)
  • NSEC3 proving non-existence of tpddns.cn/DS
  • cn/DNSKEY (alg 8, id 38388)
  • cn/DNSKEY (alg 8, id 57724)
  • cn/DS (alg 8, id 57724)

Delegation statusDelegation status

Insecure (1)
  • cn to tpddns.cn
Secure (1)
  • . to cn

NoticesNotices

Errors (5)
  • extra-six.tpddns.cn/AAAA: The response had an invalid RCODE (NOTIMP). (52.83.168.73, 52.83.170.238, UDP_-_NOEDNS_)
  • tpddns.cn zone: The following NS name(s) did not resolve to address(es): ns1.tpddns.cn
  • tpddns.cn zone: The server(s) were not responsive to queries over UDP. (120.239.199.120)
  • tpddns.cn/DNSKEY: The response (27 bytes) was malformed. (52.83.168.73, 52.83.170.238, UDP_-_EDNS0_512_D_K)
  • tpddns.cn/DNSKEY: The response had an invalid RCODE (NOTIMP). (52.83.168.73, 52.83.170.238, UDP_-_NOEDNS_)
Warnings (5)
  • . to cn: Authoritative AAAA records exist for ns.cernet.net, but there are no corresponding AAAA glue records.
  • . to cn: The glue address(es) for ns.cernet.net (202.112.0.44) differed from its authoritative address(es) (103.137.60.44).
  • cn to tpddns.cn: No response was received from the server over UDP (tried 6 times) until the COOKIE EDNS option was removed (however, this server appeared to respond legitimately to other queries with the COOKIE EDNS option present). (195.219.8.90, UDP_-_EDNS0_4096_D_K)
  • cn to tpddns.cn: The glue address(es) for ns2.tpddns.cn (52.83.170.238) differed from its authoritative address(es) (120.239.199.120).
  • extra-six.tpddns.cn/A: The response (53 bytes) was malformed until EDNS was disabled. (52.83.168.73, 52.83.170.238, UDP_-_EDNS0_4096_D_K)

DNSKEY legend

Full legend
SEP bit setSEP bit set
Revoke bit setRevoke bit set
Trust anchorTrust anchor
Download: png | svg
Warning JavaScript is required to make the graph below interactive.
DNSSEC authentication graph