NSEC3 proving non-existence of www.startpuntgeldzaken.nl/CNAME
nl/DNSKEY (alg 8, id 34112)
nl/DNSKEY (alg 8, id 59668)
nl/DS (alg 8, id 34112)
space/DNSKEY (alg 8, id 3841)
space/DNSKEY (alg 8, id 44251)
space/DNSKEY (alg 8, id 65274)
space/DS (alg 8, id 44251)
space/DS (alg 8, id 44251)
startpuntgeldzaken.nl/DNSKEY (alg 7, id 28772)
startpuntgeldzaken.nl/DNSKEY (alg 8, id 61771)
startpuntgeldzaken.nl/DS (alg 8, id 61771)
truepeople.space/DNSKEY (alg 7, id 40097)
truepeople.space/DNSKEY (alg 7, id 64134)
truepeople.space/DS (alg 7, id 64134)
Delegation status
Secure (4)
. to nl
. to space
nl to startpuntgeldzaken.nl
space to truepeople.space
Notices
Errors (4)
NSEC3 proving non-existence of www.startpuntgeldzaken.nl/CNAME: An iterations count of 0 must be used in NSEC3 records to alleviate computational burdens. See RFC 9276, Sec. 3.1.
NSEC3 proving non-existence of www.startpuntgeldzaken.nl/CNAME: An iterations count of 0 must be used in NSEC3 records to alleviate computational burdens. See RFC 9276, Sec. 3.1.
www.startpuntgeldzaken.nl/AAAA has errors; select the "Denial of existence" DNSSEC option to see them.
startpuntgeldzaken.nl/CNAME has errors; select the "Denial of existence" DNSSEC option to see them.
Warnings (17)
. to space: The following NS name(s) were found in the authoritative NS RRset, but not in the delegation NS RRset (i.e., in the . zone): g.nic.space See RFC 1034, Sec. 4.2.2.
NSEC3 proving non-existence of www.startpuntgeldzaken.nl/CNAME: The salt value for an NSEC3 record should be empty. See RFC 9276, Sec. 3.1.
NSEC3 proving non-existence of www.startpuntgeldzaken.nl/CNAME: The salt value for an NSEC3 record should be empty. See RFC 9276, Sec. 3.1.
RRSIG NSEC3 proving non-existence of www.startpuntgeldzaken.nl/CNAME alg 7, id 28772: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1). See RFC 8624, Sec. 3.1.
RRSIG _.startpuntgeldzaken.nl/CNAME alg 7, id 28772: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1). See RFC 8624, Sec. 3.1.
RRSIG nibud.truepeople.space/CNAME alg 7, id 40097: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1). See RFC 8624, Sec. 3.1.
RRSIG startpuntgeldzaken.nl/DNSKEY alg 7, id 28772: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1). See RFC 8624, Sec. 3.1.
RRSIG startpuntgeldzaken.nl/DNSKEY alg 7, id 28772: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1). See RFC 8624, Sec. 3.1.
RRSIG tp-nibud-01.truepeople.space/A alg 7, id 40097: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1). See RFC 8624, Sec. 3.1.
RRSIG truepeople.space/DNSKEY alg 7, id 64134: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1). See RFC 8624, Sec. 3.1.
RRSIG truepeople.space/DNSKEY alg 7, id 64134: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 7 (RSASHA1NSEC3SHA1). See RFC 8624, Sec. 3.1.
space/DS (alg 8, id 44251): DNSSEC implementers are prohibited from implementing signing with DS algorithm 1 (SHA-1). See RFC 8624, Sec. 3.2.
space/DS (alg 8, id 44251): DNSSEC implementers are prohibited from implementing signing with DS algorithm 1 (SHA-1). See RFC 8624, Sec. 3.2.
space/DS (alg 8, id 44251): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset. See RFC 4509, Sec. 3.
space/DS (alg 8, id 44251): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset. See RFC 4509, Sec. 3.
www.startpuntgeldzaken.nl/AAAA has warnings; select the "Denial of existence" DNSSEC option to see them.
startpuntgeldzaken.nl/CNAME has warnings; select the "Denial of existence" DNSSEC option to see them.