View on GitHub

DNSViz: A DNS visualization tool

udg.edu.me

Updated: 2020-10-14 08:50:18 UTC (1301 days ago) Update now
« Previous analysis | Next analysis »
DNSSEC options (hide)
  1. |?|
  2. |?|
  3. |?|
  4. |?|
  5. |?|
  6. |?|
  7. |?|
Notices
DNSSEC Authentication Chain

RRset statusRRset status

Insecure (12)
  • edu.me/SOA
  • udg.edu.me/A
  • udg.edu.me/A (NODATA)
  • udg.edu.me/AAAA
  • udg.edu.me/AAAA (NODATA)
  • udg.edu.me/MX
  • udg.edu.me/MX
  • udg.edu.me/NS
  • udg.edu.me/SOA
  • udg.edu.me/SOA
  • udg.edu.me/TXT
  • udg.edu.me/TXT
Secure (2)
  • me/SOA
  • me/SOA

DNSKEY/DS/NSEC statusDNSKEY/DS/NSEC status

Secure (9)
  • ./DNSKEY (alg 8, id 20326)
  • ./DNSKEY (alg 8, id 26116)
  • NSEC3 proving non-existence of edu.me/DS
  • me/DNSKEY (alg 7, id 50310)
  • me/DNSKEY (alg 7, id 53233)
  • me/DNSKEY (alg 8, id 44634)
  • me/DNSKEY (alg 8, id 45352)
  • me/DS (alg 7, id 2569)
  • me/DS (alg 7, id 53233)
Non_existent (1)
  • me/DNSKEY (alg 7, id 2569)

Delegation statusDelegation status

Insecure (2)
  • edu.me to udg.edu.me
  • me to edu.me
Secure (1)
  • . to me

NoticesNotices

Errors (3)
  • edu.me zone: The following NS name(s) did not resolve to address(es): ns2.edu.me
  • edu.me zone: The server(s) were not responsive to queries over UDP. (89.188.39.223)
  • me/DNSKEY: No response was received from the server over UDP (tried 4 times). (199.253.59.1, UDP_-_EDNS0_512_D_K)
Warnings (13)
  • RRSIG NSEC3 proving non-existence of edu.me/DS alg 7, id 50310: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
  • RRSIG NSEC3 proving non-existence of edu.me/DS alg 7, id 50310: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
  • RRSIG NSEC3 proving non-existence of edu.me/DS alg 7, id 50310: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
  • RRSIG me/DNSKEY alg 7, id 53233: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
  • RRSIG me/DNSKEY alg 7, id 53233: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
  • RRSIG me/DNSKEY alg 7, id 53233: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
  • RRSIG me/DNSKEY alg 7, id 53233: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
  • RRSIG me/SOA alg 7, id 50310: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
  • RRSIG me/SOA alg 7, id 50310: DNSSEC specification recommends not signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1).
  • edu.me to udg.edu.me: The following NS name(s) were found in the authoritative NS RRset, but not in the delegation NS RRset (i.e., in the edu.me zone): irma.ns.cloudflare.com, jason.ns.cloudflare.com
  • edu.me to udg.edu.me: The following NS name(s) were found in the delegation NS RRset (i.e., in the edu.me zone), but not in the authoritative NS RRset: mail.edu.me, ns.edu.me
  • me to edu.me: The following NS name(s) were found in the authoritative NS RRset, but not in the delegation NS RRset (i.e., in the me zone): mail.edu.me, ns.ac.me
  • me to edu.me: The following NS name(s) were found in the delegation NS RRset (i.e., in the me zone), but not in the authoritative NS RRset: ns2.edu.me

DNSKEY legend

Full legend
SEP bit setSEP bit set
Revoke bit setRevoke bit set
Trust anchorTrust anchor
Download: png | svg
Warning JavaScript is required to make the graph below interactive.
DNSSEC authentication graph