View on GitHub

DNSViz: A DNS visualization tool

studenka-headquarters.run.place

« Previous analysis | Next analysis »
DNSSEC options (hide)
  1. |?|
  2. |?|
  3. |?|
  4. |?|
  5. |?|
  6. |?|
  7. |?|
  8. |?|
  9. |?|
  10. |?|
Notices
DNSSEC Authentication Chain

RRset statusRRset status

Insecure (19)
  • run.place/A
  • run.place/A
  • run.place/A (NODATA)
  • run.place/MX
  • run.place/MX (NODATA)
  • run.place/NS
  • run.place/NS (NODATA)
  • run.place/SOA
  • run.place/SOA (NODATA)
  • run.place/TXT
  • studenka-headquarters.run.place/A
  • studenka-headquarters.run.place/A (NODATA)
  • studenka-headquarters.run.place/CNAME
  • studenka-headquarters.run.place/MX (NODATA)
  • studenka-headquarters.run.place/NS
  • studenka-headquarters.run.place/NS (NODATA)
  • studenka-headquarters.run.place/SOA
  • studenka-headquarters.run.place/SOA (NODATA)
  • studenka-headquarters.run.place/TXT (NODATA)
Secure (1)
  • place/SOA

DNSKEY/DS/NSEC statusDNSKEY/DS/NSEC status

Secure (8)
  • ./DNSKEY (alg 8, id 20326)
  • ./DNSKEY (alg 8, id 38696)
  • ./DNSKEY (alg 8, id 53148)
  • NSEC3 proving non-existence of run.place/DS
  • place/DNSKEY (alg 8, id 33993)
  • place/DNSKEY (alg 8, id 41538)
  • place/DNSKEY (alg 8, id 436)
  • place/DS (alg 8, id 436)

Delegation statusDelegation status

Bogus (1)
  • run.place to studenka-headquarters.run.place
Insecure (1)
  • place to run.place
Secure (1)
  • . to place

NoticesNotices

Errors (26)
  • run.place to studenka-headquarters.run.place: No delegation NS records were detected in the parent zone (run.place). This results in an NXDOMAIN response to a DS query (for DNSSEC), even if the parent servers are authoritative for the child. See RFC 1034, Sec. 4.2.2. (204.12.239.138, UDP_-_EDNS0_4096_D_KN)
  • run.place to studenka-headquarters.run.place: The NODATA response did not include an SOA record. See RFC 1034, Sec. 4.3.4, RFC 2308, Sec. 2.2. (31.14.40.88, UDP_-_EDNS0_4096_D_KN)
  • run.place zone: The following NS name(s) did not resolve to address(es): ns11.dnsexit.com, ns12.dnsexit.com, ns13.dnsexit.com
  • run.place zone: The server(s) did not respond authoritatively for the namespace. See RFC 1035, Sec. 4.1.1. (31.14.40.88)
  • run.place/A (NODATA): The Authoritative Answer (AA) flag was not set in the response. See RFC 1035, Sec. 4.1.1. (31.14.40.88, UDP_-_EDNS0_4096_D_KN)
  • run.place/A (NODATA): The NODATA response did not include an SOA record. See RFC 1034, Sec. 4.3.4, RFC 2308, Sec. 2.2. (31.14.40.88, UDP_-_EDNS0_4096_D_KN)
  • run.place/MX: The Authoritative Answer (AA) flag was not set in the response. See RFC 1035, Sec. 4.1.1. (31.14.40.88, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_512_D_KN)
  • run.place/NS (NODATA): The Authoritative Answer (AA) flag was not set in the response. See RFC 1035, Sec. 4.1.1. (31.14.40.88, UDP_-_EDNS0_4096_D_KN)
  • run.place/NS (NODATA): The NODATA response did not include an SOA record. See RFC 1034, Sec. 4.3.4, RFC 2308, Sec. 2.2. (31.14.40.88, UDP_-_EDNS0_4096_D_KN)
  • run.place/SOA (NODATA): The Authoritative Answer (AA) flag was not set in the response. See RFC 1035, Sec. 4.1.1. (31.14.40.88, TCP_-_EDNS0_4096_D_N, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_4096_D_KN_0x20)
  • run.place/SOA (NODATA): The NODATA response did not include an SOA record. See RFC 1034, Sec. 4.3.4, RFC 2308, Sec. 2.2. (31.14.40.88, TCP_-_EDNS0_4096_D_N, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_4096_D_KN_0x20)
  • run.place/TXT: The Authoritative Answer (AA) flag was not set in the response. See RFC 1035, Sec. 4.1.1. (31.14.40.88, UDP_-_EDNS0_4096_D_KN)
  • studenka-headquarters.run.place zone: The server(s) did not respond authoritatively for the namespace. See RFC 1035, Sec. 4.1.1. (31.14.40.88)
  • studenka-headquarters.run.place/A (NODATA): The response was an upward referral. See https://www.dns-oarc.net/oarc/articles/upward-referrals-considered-harmful. (31.14.40.88, UDP_-_EDNS0_4096_D_KN)
  • studenka-headquarters.run.place/MX (NODATA): The response was an upward referral. See https://www.dns-oarc.net/oarc/articles/upward-referrals-considered-harmful. (31.14.40.88, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_512_D_KN)
  • studenka-headquarters.run.place/NS (NODATA): The response was an upward referral. See https://www.dns-oarc.net/oarc/articles/upward-referrals-considered-harmful. (31.14.40.88, UDP_-_EDNS0_4096_D_KN)
  • studenka-headquarters.run.place/SOA (NODATA): The response was an upward referral. See https://www.dns-oarc.net/oarc/articles/upward-referrals-considered-harmful. (31.14.40.88, TCP_-_EDNS0_4096_D_N, UDP_-_EDNS0_4096_D_KN, UDP_-_EDNS0_4096_D_KN_0x20)
  • studenka-headquarters.run.place/TXT (NODATA): The response was an upward referral. See https://www.dns-oarc.net/oarc/articles/upward-referrals-considered-harmful. (31.14.40.88, UDP_-_EDNS0_4096_D_KN)
  • studenka-headquarters.run.place/CNAME has errors; select the "Denial of existence" DNSSEC option to see them.
  • studenka-headquarters.run.place/DNSKEY has errors; select the "Denial of existence" DNSSEC option to see them.
  • studenka-headquarters.run.place/DS has errors; select the "Denial of existence" DNSSEC option to see them.
  • studenka-headquarters.run.place/NSEC3PARAM has errors; select the "Denial of existence" DNSSEC option to see them.
  • studenka-headquarters.run.place/CDS has errors; select the "Denial of existence" DNSSEC option to see them.
  • studenka-headquarters.run.place/CDNSKEY has errors; select the "Denial of existence" DNSSEC option to see them.
  • studenka-headquarters.run.place/AAAA has errors; select the "Denial of existence" DNSSEC option to see them.
  • 4x0tv.e5qhc.studenka-headquarters.run.place/A has errors; select the "Denial of existence" DNSSEC option to see them.
Warnings (13)
  • NSEC3 proving non-existence of run.place/DS: The salt value for an NSEC3 record should be empty. See RFC 9276, Sec. 3.1.
  • NSEC3 proving non-existence of run.place/DS: The salt value for an NSEC3 record should be empty. See RFC 9276, Sec. 3.1.
  • place to run.place: The following NS name(s) were found in the authoritative NS RRset, but not in the delegation NS RRset (i.e., in the place zone): ns4.dnsexit.com, ns1.dnsexit.com, ns2.dnsexit.com, ns3.dnsexit.com See RFC 1034, Sec. 4.2.2.
  • place to run.place: The following NS name(s) were found in the delegation NS RRset (i.e., in the place zone), but not in the authoritative NS RRset: ns10.dnsexit.com, ns11.dnsexit.com, ns12.dnsexit.com, ns13.dnsexit.com See RFC 1034, Sec. 4.2.2.
  • run.place to studenka-headquarters.run.place: The Authoritative Answer (AA) flag was not set in the response. See RFC 1035, Sec. 4.1.1. (31.14.40.88, UDP_-_EDNS0_4096_D_KN)
  • studenka-headquarters.run.place/CNAME: The server returned CNAME for studenka-headquarters.run.place, but records of other types exist at that name. See RFC 2181, Sec. 10.1.
  • studenka-headquarters.run.place/CNAME has warnings; select the "Denial of existence" DNSSEC option to see them.
  • studenka-headquarters.run.place/DNSKEY has warnings; select the "Denial of existence" DNSSEC option to see them.
  • studenka-headquarters.run.place/DS has warnings; select the "Denial of existence" DNSSEC option to see them.
  • studenka-headquarters.run.place/NSEC3PARAM has warnings; select the "Denial of existence" DNSSEC option to see them.
  • studenka-headquarters.run.place/CDS has warnings; select the "Denial of existence" DNSSEC option to see them.
  • studenka-headquarters.run.place/CDNSKEY has warnings; select the "Denial of existence" DNSSEC option to see them.
  • studenka-headquarters.run.place/AAAA has warnings; select the "Denial of existence" DNSSEC option to see them.

DNSKEY legend

Full legend
SEP bit setSEP bit set
Revoke bit setRevoke bit set
Trust anchorTrust anchor
Download: png | svg
Warning JavaScript is required to make the graph below interactive.
DNSSEC authentication graph