com to zoomgov.com: No valid RRSIGs made by a key corresponding to a DS RR were found covering the DNSKEY RRset, resulting in no secure entry point (SEP) into the zone. See RFC 4035, Sec. 2.2, RFC 6840, Sec. 5.11. (108.59.161.4, 108.59.162.4, 108.59.163.4, 108.59.164.4, 2600:2000:2210::4, 2600:2000:2220::4, 2600:2000:2230::4, 2600:2000:2240::4, UDP_-_EDNS0_4096_D_KN)
com to zoomgov.com: The DS RRset for the zone included algorithm 5 (RSASHA1), but no DS RR matched a DNSKEY with algorithm 5 that signs the zone's DNSKEY RRset. See RFC 4035, Sec. 2.2, RFC 6840, Sec. 5.11. (108.59.161.4, 108.59.162.4, 108.59.163.4, 108.59.164.4, 2600:2000:2210::4, 2600:2000:2220::4, 2600:2000:2230::4, 2600:2000:2240::4, UDP_-_EDNS0_4096_D_KN)
Warnings (7)
RRSIG www.zoomgov.com/A alg 5, id 63303: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 5 (RSASHA1). See RFC 8624, Sec. 3.1.
RRSIG zoomgov.com/DNSKEY alg 5, id 27451: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 5 (RSASHA1). See RFC 8624, Sec. 3.1.
RRSIG zoomgov.com/DNSKEY alg 5, id 27451: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 5 (RSASHA1). See RFC 8624, Sec. 3.1.
RRSIG zoomgov.com/DNSKEY alg 5, id 63303: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 5 (RSASHA1). See RFC 8624, Sec. 3.1.
RRSIG zoomgov.com/DNSKEY alg 5, id 63303: DNSSEC implementers are recommended against implementing signing with DNSSEC algorithm 5 (RSASHA1). See RFC 8624, Sec. 3.1.
www.zoomgov.com/AAAA has warnings; select the "Denial of existence" DNSSEC option to see them.
zoomgov.com/CNAME has warnings; select the "Denial of existence" DNSSEC option to see them.