Back to Verisign Labs Tools
Domain Name: Detail: more(+) / less(-) Time: 2024-05-13 17:08:54 UTC

Analyzing DNSSEC problems for glb.cdc.gov

.
Found 2 DNSKEY records for .
DS=20326/SHA-256 verifies DNSKEY=20326/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=20326 and DNSKEY=20326/SEP verifies the DNSKEY RRset
gov
Found 1 DS records for gov in the . zone
DS=64280/SHA-256 has algorithm RSASHA256
Found 1 RRSIGs over DS RRset
RRSIG=5613 and DNSKEY=5613 verifies the DS RRset
Found 2 DNSKEY records for gov
DS=64280/SHA-256 verifies DNSKEY=64280/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=64280 and DNSKEY=64280/SEP verifies the DNSKEY RRset
cdc.gov
Found 1 DS records for cdc.gov in the gov zone
DS=54678/SHA-256 has algorithm RSASHA1-NSEC3-SHA1
Found 1 RRSIGs over DS RRset
RRSIG=10104 and DNSKEY=10104 verifies the DS RRset
Found 2 DNSKEY records for cdc.gov
DS=54678/SHA-256 verifies DNSKEY=54678/SEP
Found 2 RRSIGs over DNSKEY RRset
RRSIG=33957 and DNSKEY=33957 verifies the DNSKEY RRset
glb.cdc.gov
Found 1 DS records for glb.cdc.gov in the cdc.gov zone
DS=54573/SHA-1 uses a deprecated digest algorithm
DS=54573/SHA-1 has algorithm RSASHA1-NSEC3-SHA1
Found 1 RRSIGs over DS RRset
RRSIG=33957 and DNSKEY=33957 verifies the DS RRset
Found 2 DNSKEY records for glb.cdc.gov
DS=54573/SHA-1 verifies DNSKEY=54573/SEP
Found 2 RRSIGs over DNSKEY RRset
RRSIG=54573 expires (in 0.46 days) before end of TTL (1.00 days)
RRSIG=26033 and DNSKEY=26033 verifies the DNSKEY RRset
ns1.glb.cdc.gov is authoritative for glb.cdc.gov
Found 1 RRSIGs over SOA RRset
RRSIG=26033 and DNSKEY=26033 verifies the SOA RRset
glb.cdc.gov
ns2.glb.cdc.gov is authoritative for glb.cdc.gov
Found 1 RRSIGs over SOA RRset
RRSIG=26033 and DNSKEY=26033 verifies the SOA RRset

Move your mouse over any or symbols for remediation hints.

Want a second opinion? Test glb.cdc.gov at dnsviz.net.

DNSSEC Debugger

↓ Advanced options