ofda.gov/MX: DNSSEC was effectively downgraded because no response was received from the server over UDP (tried 11 times) with EDNS enabled. (2001:1890:8400:f00:172:31:204:69, 2001:1890:8400:f00:172:31:204:70, UDP_-_NOEDNS_)
ofda.gov/MX: No response was received from the server over UDP (tried 11 times) until EDNS was disabled (however, this server appeared to respond legitimately to other queries with EDNS enabled). (2001:1890:8400:f00:172:31:204:69, 2001:1890:8400:f00:172:31:204:70, UDP_-_EDNS0_4096_D_K)
ofda.gov/MX: No response was received from the server over UDP (tried 4 times). (2001:1890:8400:f00:172:31:204:69, 2001:1890:8400:f00:172:31:204:70, UDP_-_EDNS0_512_D_K)
ofda.gov/MX: The DNSSEC records necessary to validate the response could not be retrieved from the server. (2001:1890:8400:f00:172:31:204:69, 2001:1890:8400:f00:172:31:204:70, UDP_-_EDNS0_4096_D_K)
Warnings (17)
RRSIG ofda.gov/A alg 5, id 29140: DNSSEC specification recommends not signing with DNSSEC algorithm 5 (RSASHA1).
RRSIG ofda.gov/DNSKEY alg 5, id 24203: DNSSEC specification recommends not signing with DNSSEC algorithm 5 (RSASHA1).
RRSIG ofda.gov/DNSKEY alg 5, id 24203: DNSSEC specification recommends not signing with DNSSEC algorithm 5 (RSASHA1).
RRSIG ofda.gov/DNSKEY alg 5, id 29140: DNSSEC specification recommends not signing with DNSSEC algorithm 5 (RSASHA1).
RRSIG ofda.gov/DNSKEY alg 5, id 29140: DNSSEC specification recommends not signing with DNSSEC algorithm 5 (RSASHA1).
RRSIG ofda.gov/MX alg 5, id 29140: DNSSEC specification recommends not signing with DNSSEC algorithm 5 (RSASHA1).
RRSIG ofda.gov/NS alg 5, id 29140: DNSSEC specification recommends not signing with DNSSEC algorithm 5 (RSASHA1).
RRSIG ofda.gov/SOA alg 5, id 29140: DNSSEC specification recommends not signing with DNSSEC algorithm 5 (RSASHA1).
RRSIG ofda.gov/TXT alg 5, id 29140: DNSSEC specification recommends not signing with DNSSEC algorithm 5 (RSASHA1).
gov/DS (alg 8, id 7698): DNSSEC specification prohibits signing with DS records that use digest algorithm 1 (SHA-1).
gov/DS (alg 8, id 7698): DNSSEC specification prohibits signing with DS records that use digest algorithm 1 (SHA-1).
gov/DS (alg 8, id 7698): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset.
gov/DS (alg 8, id 7698): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset.
ofda.gov/DS (alg 5, id 24203): DNSSEC specification prohibits signing with DS records that use digest algorithm 1 (SHA-1).
ofda.gov/DS (alg 5, id 24203): DNSSEC specification prohibits signing with DS records that use digest algorithm 1 (SHA-1).
ofda.gov/DS (alg 5, id 24203): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset.
ofda.gov/DS (alg 5, id 24203): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset.