RRSIG peacecorpsoig.gov/NS alg 8, id 14151: The cryptographic signature of the RRSIG RR does not properly validate. See RFC 4035, Sec. 5.3.3.
RRSIG peacecorpsoig.gov/SOA alg 8, id 14151: The cryptographic signature of the RRSIG RR does not properly validate. See RFC 4035, Sec. 5.3.3.
gov to peacecorpsoig.gov: No valid RRSIGs made by a key corresponding to a DS RR were found covering the DNSKEY RRset, resulting in no secure entry point (SEP) into the zone. See RFC 4035, Sec. 2.2, RFC 6840, Sec. 5.11. (192.230.121.1, 192.230.122.1, 192.230.123.1, 2a02:e980:4::1, 2a02:e980:5::1, 2a02:e980:6::1, UDP_-_EDNS0_4096_D_KN)
gov to peacecorpsoig.gov: The DS RRset for the zone included algorithm 8 (RSASHA256), but no DS RR matched a DNSKEY with algorithm 8 that signs the zone's DNSKEY RRset. See RFC 4035, Sec. 2.2, RFC 6840, Sec. 5.11. (192.230.121.1, 192.230.122.1, 192.230.123.1, 2a02:e980:4::1, 2a02:e980:5::1, 2a02:e980:6::1, UDP_-_EDNS0_4096_D_KN)
peacecorpsoig.gov/NSEC3PARAM has errors; select the "Denial of existence" DNSSEC option to see them.
peacecorpsoig.gov/CNAME has errors; select the "Denial of existence" DNSSEC option to see them.
jy1q6kvpb0.peacecorpsoig.gov/A has errors; select the "Denial of existence" DNSSEC option to see them.
peacecorpsoig.gov/AAAA has errors; select the "Denial of existence" DNSSEC option to see them.
Warnings (2)
gov to peacecorpsoig.gov: The following NS name(s) were found in the delegation NS RRset (i.e., in the gov zone), but not in the authoritative NS RRset: ns1.a2.impervasecuredns.net See RFC 1034, Sec. 4.2.2.
peacecorpsoig.gov/SOA: The server set EDNS flags that are undefined: 0x7fbc. See RFC 6891, Sec. 6.1.4. (2a02:e980:4::1, 2a02:e980:5::1, 2a02:e980:6::1, TCP_-_EDNS0_4096_D_N, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_4096_D_KN_0x20)