RRSIG d1a3n1.rootcanary.net/DNSKEY alg 3, id 26281: DNSSEC implementers are prohibited from implementing signing with DNSSEC algorithm 3 (DSA). See RFC 8624, Sec. 3.1.
RRSIG d1a3n1.rootcanary.net/DNSKEY alg 3, id 26281: DNSSEC implementers are prohibited from implementing validation of DNSSEC algorithm 3 (DSA). See RFC 8624, Sec. 3.1.
RRSIG secure.d1a3n1.rootcanary.net/A alg 3, id 26281: DNSSEC implementers are prohibited from implementing signing with DNSSEC algorithm 3 (DSA). See RFC 8624, Sec. 3.1.
RRSIG secure.d1a3n1.rootcanary.net/A alg 3, id 26281: DNSSEC implementers are prohibited from implementing validation of DNSSEC algorithm 3 (DSA). See RFC 8624, Sec. 3.1.
RRSIG secure.d1a3n1.rootcanary.net/AAAA alg 3, id 26281: DNSSEC implementers are prohibited from implementing signing with DNSSEC algorithm 3 (DSA). See RFC 8624, Sec. 3.1.
RRSIG secure.d1a3n1.rootcanary.net/AAAA alg 3, id 26281: DNSSEC implementers are prohibited from implementing validation of DNSSEC algorithm 3 (DSA). See RFC 8624, Sec. 3.1.
d1a3n1.rootcanary.net/DS (alg 3, id 26281): DNSSEC implementers are prohibited from implementing signing with DS algorithm 1 (SHA-1). See RFC 8624, Sec. 3.2.
d1a3n1.rootcanary.net/DS (alg 3, id 26281): DNSSEC implementers are prohibited from implementing signing with DS algorithm 1 (SHA-1). See RFC 8624, Sec. 3.2.
d1a3n1.rootcanary.net/CNAME has warnings; select the "Denial of existence" DNSSEC option to see them.