View on GitHub
smokefree.gov
Updated:
2023-03-22 00:27:46 UTC
(
413 days ago
)
Go to most recent »
« Previous analysis
|
Next analysis »
Tweet
DNSSEC
Responses
Servers
Analyze
DNSSEC options (
hide
)
|?|
RR types:
--All--
A
AAAA
TXT
PTR
MX
NS
SOA
CNAME
SRV
NAPTR
TLSA
NSEC3PARAM
CAA
|?|
DNSSEC algorithms:
--All--
1 - RSA/MD5
3 - DSA/SHA1
5 - RSA/SHA-1
6 - DSA-NSEC3-SHA1
7 - RSASHA1-NSEC3-SHA1
8 - RSA/SHA-256
10 - RSA/SHA-512
12 - GOST R 34.10-2001
13 - ECDSA Curve P-256 with SHA-256
14 - ECDSA Curve P-384 with SHA-384
15 - Ed25519
16 - Ed448
|?|
DS digest algorithms:
--All--
1 - SHA-1
2 - SHA-256
3 - GOST R 34.11-94
4 - SHA-384
|?|
Denial of existence:
|?|
Redundant edges:
|?|
Trust anchors:
Root zone KSK
|?|
Additional trusted keys:
Notices
DNSSEC Authentication Chain
RRset status
Insecure
(6)
smokefree.gov/A
smokefree.gov/AAAA
smokefree.gov/NS
smokefree.gov/NSEC3PARAM
smokefree.gov/SOA
smokefree.gov/TXT
Secure
(1)
gov/SOA
DNSKEY/DS/NSEC status
Insecure
(4)
smokefree.gov/DNSKEY (alg 7, id 19824)
smokefree.gov/DNSKEY (alg 7, id 30230)
smokefree.gov/DNSKEY (alg 7, id 7805)
smokefree.gov/DNSKEY (alg 7, id 7809)
Secure
(6)
./DNSKEY (alg 8, id 20326)
./DNSKEY (alg 8, id 951)
NSEC3 proving non-existence of smokefree.gov/DS
gov/DNSKEY (alg 8, id 24250)
gov/DNSKEY (alg 8, id 7698)
gov/DS (alg 8, id 7698)
Delegation status
Insecure
(1)
gov to smokefree.gov
Secure
(1)
. to gov
Notices
Warnings
(31)
RRSIG smokefree.gov/A alg 7, id 30230: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/A alg 7, id 7805: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/AAAA alg 7, id 30230: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/AAAA alg 7, id 7805: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/DNSKEY alg 7, id 19824: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/DNSKEY alg 7, id 19824: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/DNSKEY alg 7, id 19824: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/DNSKEY alg 7, id 19824: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/DNSKEY alg 7, id 30230: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/DNSKEY alg 7, id 30230: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/DNSKEY alg 7, id 30230: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/DNSKEY alg 7, id 30230: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/DNSKEY alg 7, id 7805: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/DNSKEY alg 7, id 7805: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/DNSKEY alg 7, id 7805: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/DNSKEY alg 7, id 7805: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/DNSKEY alg 7, id 7809: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/DNSKEY alg 7, id 7809: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/DNSKEY alg 7, id 7809: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/DNSKEY alg 7, id 7809: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/NS alg 7, id 30230: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/NS alg 7, id 7805: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/NSEC3PARAM alg 7, id 30230: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/NSEC3PARAM alg 7, id 7805: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/SOA alg 7, id 30230: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/SOA alg 7, id 7805: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/TXT alg 7, id 30230: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
RRSIG smokefree.gov/TXT alg 7, id 7805: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
gov to smokefree.gov: Authoritative AAAA records exist for ns.nih.gov, but there are no corresponding AAAA glue records.
gov to smokefree.gov: Authoritative AAAA records exist for ns2.nih.gov, but there are no corresponding AAAA glue records.
gov to smokefree.gov: Authoritative AAAA records exist for ns3.nih.gov, but there are no corresponding AAAA glue records.
DNSKEY legend
Full legend
SEP bit set
Revoke bit set
Trust anchor
See also
DNSSEC Debugger
by
Verisign Labs
.
Download:
png
|
svg
JavaScript is required to make the graph below interactive.