View on GitHub

DNSViz: A DNS visualization tool

nic.mm

Updated: 2025-03-30 21:32:01 UTC (8 days ago) Update now
« Previous analysis | Next analysis »
DNSSEC options (hide)
  1. |?|
  2. |?|
  3. |?|
  4. |?|
  5. |?|
  6. |?|
  7. |?|
  8. |?|
  9. |?|
  10. |?|
Notices
DNSSEC Authentication Chain

RRset statusRRset status

Bogus (1)
  • nic.mm/A (NXDOMAIN)
Secure (1)
  • mm/SOA

DNSKEY/DS/NSEC statusDNSKEY/DS/NSEC status

Bogus (1)
  • NSEC3 proving non-existence of nic.mm/A
Secure (7)
  • ./DNSKEY (alg 8, id 20326)
  • ./DNSKEY (alg 8, id 26470)
  • ./DNSKEY (alg 8, id 38696)
  • ./DNSKEY (alg 8, id 53148)
  • mm/DNSKEY (alg 8, id 18589)
  • mm/DNSKEY (alg 8, id 32298)
  • mm/DS (alg 8, id 18589)

Delegation statusDelegation status

Secure (1)
  • . to mm

NoticesNotices

Errors (6)
  • NSEC3 proving non-existence of nic.mm/A: An iterations count of 0 must be used in NSEC3 records to alleviate computational burdens. See RFC 9276, Sec. 3.1.
  • NSEC3 proving non-existence of nic.mm/A: An iterations count of 0 must be used in NSEC3 records to alleviate computational burdens. See RFC 9276, Sec. 3.1.
  • RRSIG NSEC3 proving non-existence of nic.mm/A alg 8, id 32298: The Signature Expiration field of the RRSIG RR (2025-03-30 09:21:55+00:00) is 12 hours, 10 minutes in the past. See RFC 4035, Sec. 5.3.1.
  • RRSIG NSEC3 proving non-existence of nic.mm/A alg 8, id 32298: The Signature Expiration field of the RRSIG RR (2025-03-30 15:21:23+00:00) is 6 hours, 10 minutes in the past. See RFC 4035, Sec. 5.3.1.
  • mm zone: The server(s) were not responsive to queries over UDP. See RFC 1035, Sec. 4.2. (103.103.173.9)
  • mm/CNAME has errors; select the "Denial of existence" DNSSEC option to see them.
Warnings (3)
  • NSEC3 proving non-existence of nic.mm/A: The salt value for an NSEC3 record should be empty. See RFC 9276, Sec. 3.1.
  • NSEC3 proving non-existence of nic.mm/A: The salt value for an NSEC3 record should be empty. See RFC 9276, Sec. 3.1.
  • mm/CNAME has warnings; select the "Denial of existence" DNSSEC option to see them.

DNSKEY legend

Full legend
SEP bit setSEP bit set
Revoke bit setRevoke bit set
Trust anchorTrust anchor
Download: png | svg
Warning JavaScript is required to make the graph below interactive.
DNSSEC authentication graph