View on GitHub

DNSViz: A DNS visualization tool

x8x9zq3n.s3.amazonaws.com

Updated: 2020-09-25 12:47:13 UTC (1356 days ago) Update now
« Previous analysis | Next analysis »
DNSSEC options (hide)
  1. |?|
  2. |?|
  3. |?|
  4. |?|
  5. |?|
  6. |?|
  7. |?|
  8. |?|
  9. |?|
Notices
DNSSEC Authentication Chain

RRset statusRRset status

Insecure (10)
  • amazonaws.com/SOA
  • s3-1-w.amazonaws.com/A
  • s3-1-w.amazonaws.com/A
  • s3-1-w.amazonaws.com/A
  • s3-1-w.amazonaws.com/A
  • s3-1-w.amazonaws.com/A
  • s3-1-w.amazonaws.com/A
  • s3-1-w.amazonaws.com/A
  • s3-1-w.amazonaws.com/A
  • x8x9zq3n.s3.amazonaws.com/CNAME
Secure (2)
  • com/SOA
  • com/SOA

DNSKEY/DS/NSEC statusDNSKEY/DS/NSEC status

Secure (7)
  • ./DNSKEY (alg 8, id 20326)
  • ./DNSKEY (alg 8, id 26116)
  • ./DNSKEY (alg 8, id 46594)
  • NSEC3 proving non-existence of amazonaws.com/DS
  • com/DNSKEY (alg 8, id 24966)
  • com/DNSKEY (alg 8, id 30909)
  • com/DS (alg 8, id 30909)

Delegation statusDelegation status

Insecure (3)
  • amazonaws.com to s3-1-w.amazonaws.com
  • amazonaws.com to s3.amazonaws.com
  • com to amazonaws.com
Secure (1)
  • . to com

NoticesNotices

Warnings (2)
  • amazonaws.com to s3-1-w.amazonaws.com: The server(s) for the parent zone (amazonaws.com) responded with a referral instead of answering authoritatively for the DS RR type. See RFC 4034, Sec. 5. (205.251.192.27, 205.251.195.199, 2600:9000:5300:1b00::1, 2600:9000:5303:c700::1, UDP_-_EDNS0_4096_D_K)
  • amazonaws.com to s3.amazonaws.com: The server(s) for the parent zone (amazonaws.com) responded with a referral instead of answering authoritatively for the DS RR type. See RFC 4034, Sec. 5. (205.251.192.27, 205.251.195.199, 2600:9000:5300:1b00::1, 2600:9000:5303:c700::1, UDP_-_EDNS0_4096_D_K)

DNSKEY legend

Full legend
SEP bit setSEP bit set
Revoke bit setRevoke bit set
Trust anchorTrust anchor
Download: png | svg
Warning JavaScript is required to make the graph below interactive.
DNSSEC authentication graph