View on GitHub

DNSViz: A DNS visualization tool

fw.fast.za.net

Updated: 2024-09-02 13:53:02 UTC (471 days ago) Update now
« Previous analysis | Next analysis »
DNSSEC options (hide)
  1. |?|
  2. |?|
  3. |?|
  4. |?|
  5. |?|
  6. |?|
  7. |?|
  8. |?|
  9. |?|
  10. |?|
Notices
DNSSEC Authentication Chain

RRset statusRRset status

Insecure (2)
  • fw.fast.za.net/A
  • za.net/SOA
Secure (2)
  • net/SOA
  • net/SOA

DNSKEY/DS/NSEC statusDNSKEY/DS/NSEC status

Insecure (4)
  • fast.za.net/DNSKEY (alg 13, id 19923)
  • fast.za.net/DNSKEY (alg 13, id 39039)
  • fast.za.net/DNSKEY (alg 8, id 2103)
  • fast.za.net/DNSKEY (alg 8, id 41471)
Secure (6)
  • ./DNSKEY (alg 8, id 20038)
  • ./DNSKEY (alg 8, id 20326)
  • NSEC3 proving non-existence of za.net/DS
  • net/DNSKEY (alg 13, id 37331)
  • net/DNSKEY (alg 13, id 42924)
  • net/DS (alg 13, id 37331)

Delegation statusDelegation status

Insecure (2)
  • net to za.net
  • za.net to fast.za.net
Secure (1)
  • . to net

NoticesNotices

Errors (6)
  • fast.za.net/DNSKEY (alg 13, id 39039): The DNSKEY RR was not found in the DNSKEY RRset returned by one or more servers. (45.58.122.83, 54.36.109.15, 95.141.37.127, 195.154.94.174, 199.119.202.75, 2001:bc8:6006:4000:8218:44ff:feef:d720, 2001:41d0:700:120f::1, 2604:6600:0:1b::2, 2605:9880:300:1400:101:1650:5e2:54, 2a02:29e0:1:103:103::1, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_512_D_KN)
  • fast.za.net/DNSKEY (alg 8, id 2103): The DNSKEY RR was not found in the DNSKEY RRset returned by one or more servers. (45.58.122.83, 54.36.109.15, 95.141.37.127, 195.154.94.174, 199.119.202.75, 2001:bc8:6006:4000:8218:44ff:feef:d720, 2001:41d0:700:120f::1, 2604:6600:0:1b::2, 2605:9880:300:1400:101:1650:5e2:54, 2a02:29e0:1:103:103::1, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_512_D_KN)
  • fw.fast.za.net/A: No RRSIG covering the RRset was returned in the response. See RFC 4035, Sec. 3.1.1. (45.58.122.83, 54.36.109.15, 95.141.37.127, 195.154.94.174, 199.119.202.75, 2001:bc8:6006:4000:8218:44ff:feef:d720, 2001:41d0:700:120f::1, 2604:6600:0:1b::2, 2605:9880:300:1400:101:1650:5e2:54, 2a02:29e0:1:103:103::1, UDP_-_EDNS0_4096_D_KN)
  • za.net zone: The server(s) were not responsive to queries over UDP. See RFC 1035, Sec. 4.2. (2c0e:2001:4000:1::c419:101)
  • fw.fast.za.net/AAAA has errors; select the "Denial of existence" DNSSEC option to see them.
  • fast.za.net/CNAME has errors; select the "Denial of existence" DNSSEC option to see them.
Warnings (15)
  • RRSIG fast.za.net/DNSKEY alg 13, id 19923: The value of the Signature Inception field of the RRSIG RR (2024-09-02 13:52:39+00:00) is within possible clock skew range (19 seconds) of the current time (2024-09-02 13:52:58+00:00). See RFC 4035, Sec. 5.3.1.
  • RRSIG fast.za.net/DNSKEY alg 13, id 19923: The value of the Signature Inception field of the RRSIG RR (2024-09-02 13:52:39+00:00) is within possible clock skew range (19 seconds) of the current time (2024-09-02 13:52:58+00:00). See RFC 4035, Sec. 5.3.1.
  • RRSIG fast.za.net/DNSKEY alg 13, id 19923: The value of the Signature Inception field of the RRSIG RR (2024-09-02 13:52:39+00:00) is within possible clock skew range (19 seconds) of the current time (2024-09-02 13:52:58+00:00). See RFC 4035, Sec. 5.3.1.
  • RRSIG fast.za.net/DNSKEY alg 13, id 19923: The value of the Signature Inception field of the RRSIG RR (2024-09-02 13:52:39+00:00) is within possible clock skew range (19 seconds) of the current time (2024-09-02 13:52:58+00:00). See RFC 4035, Sec. 5.3.1.
  • RRSIG fast.za.net/DNSKEY alg 8, id 41471: The value of the Signature Inception field of the RRSIG RR (2024-09-02 13:52:39+00:00) is within possible clock skew range (19 seconds) of the current time (2024-09-02 13:52:58+00:00). See RFC 4035, Sec. 5.3.1.
  • RRSIG fast.za.net/DNSKEY alg 8, id 41471: The value of the Signature Inception field of the RRSIG RR (2024-09-02 13:52:39+00:00) is within possible clock skew range (19 seconds) of the current time (2024-09-02 13:52:58+00:00). See RFC 4035, Sec. 5.3.1.
  • RRSIG fast.za.net/DNSKEY alg 8, id 41471: The value of the Signature Inception field of the RRSIG RR (2024-09-02 13:52:39+00:00) is within possible clock skew range (19 seconds) of the current time (2024-09-02 13:52:58+00:00). See RFC 4035, Sec. 5.3.1.
  • RRSIG fast.za.net/DNSKEY alg 8, id 41471: The value of the Signature Inception field of the RRSIG RR (2024-09-02 13:52:39+00:00) is within possible clock skew range (19 seconds) of the current time (2024-09-02 13:52:58+00:00). See RFC 4035, Sec. 5.3.1.
  • RRSIG fw.fast.za.net/A alg 13, id 39039: The value of the Signature Inception field of the RRSIG RR (2024-09-02 13:52:39+00:00) is within possible clock skew range (23 seconds) of the current time (2024-09-02 13:53:02+00:00). See RFC 4035, Sec. 5.3.1.
  • RRSIG fw.fast.za.net/A alg 8, id 2103: The value of the Signature Inception field of the RRSIG RR (2024-09-02 13:52:39+00:00) is within possible clock skew range (23 seconds) of the current time (2024-09-02 13:53:02+00:00). See RFC 4035, Sec. 5.3.1.
  • fast.za.net/DNSKEY (alg 13, id 19923): The DNSKEY RR was not found in the DNSKEY RRset returned by one or more servers. (45.58.122.83, 54.36.109.15, 95.141.37.127, 195.154.94.174, 199.119.202.75, 2001:bc8:6006:4000:8218:44ff:feef:d720, 2001:41d0:700:120f::1, 2604:6600:0:1b::2, 2605:9880:300:1400:101:1650:5e2:54, 2a02:29e0:1:103:103::1, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_512_D_KN)
  • fast.za.net/DNSKEY (alg 8, id 41471): The DNSKEY RR was not found in the DNSKEY RRset returned by one or more servers. (45.58.122.83, 54.36.109.15, 95.141.37.127, 195.154.94.174, 199.119.202.75, 2001:bc8:6006:4000:8218:44ff:feef:d720, 2001:41d0:700:120f::1, 2604:6600:0:1b::2, 2605:9880:300:1400:101:1650:5e2:54, 2a02:29e0:1:103:103::1, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_512_D_KN)
  • za.net to fast.za.net: The following NS name(s) were found in the authoritative NS RRset, but not in the delegation NS RRset (i.e., in the za.net zone): freedns4.registrar-servers.com, freedns5.registrar-servers.com, puck.nether.net, freedns1.registrar-servers.com, freedns2.registrar-servers.com See RFC 1034, Sec. 4.2.2.
  • fw.fast.za.net/AAAA has warnings; select the "Denial of existence" DNSSEC option to see them.
  • fast.za.net/CNAME has warnings; select the "Denial of existence" DNSSEC option to see them.

DNSKEY legend

Full legend
SEP bit setSEP bit set
Revoke bit setRevoke bit set
Trust anchorTrust anchor
Download: png | svg
Warning JavaScript is required to make the graph below interactive.
DNSSEC authentication graph