Back to Verisign Labs Tools
Domain Name: Detail: more(+) / less(-) Time: 2024-05-19 16:24:16 UTC

Analyzing DNSSEC problems for sigfail.verteiltesysteme.net

.
Found 2 DNSKEY records for .
DS=20326/SHA-256 verifies DNSKEY=20326/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=20326 and DNSKEY=20326/SEP verifies the DNSKEY RRset
net
Found 1 DS records for net in the . zone
DS=37331/SHA-256 has algorithm ECDSAP256SHA256
Found 1 RRSIGs over DS RRset
RRSIG=5613 and DNSKEY=5613 verifies the DS RRset
Found 2 DNSKEY records for net
DS=37331/SHA-256 verifies DNSKEY=37331/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=37331 and DNSKEY=37331/SEP verifies the DNSKEY RRset
verteiltesysteme.net
Found 1 DS records for verteiltesysteme.net in the net zone
DS=29912/SHA-1 uses a deprecated digest algorithm
DS=29912/SHA-1 has algorithm ECDSAP256SHA256
Found 1 RRSIGs over DS RRset
RRSIG=51809 and DNSKEY=51809 verifies the DS RRset
Found 2 DNSKEY records for verteiltesysteme.net
DS=29912/SHA-1 verifies DNSKEY=29912/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=29912 and DNSKEY=29912/SEP verifies the DNSKEY RRset
dns2.registrar-servers.com is authoritative for sigfail.verteiltesysteme.net
sigfail.verteiltesysteme.net is a CNAME to sigfail.rsa2048-sha256.ippacket.stream
Found 1 RRSIGs over CNAME RRset
RRSIG=47187 and DNSKEY=47187 verifies the CNAME RRset
.
stream
Found 1 DS records for stream in the . zone
DS=31735/SHA-256 has algorithm RSASHA256
Found 1 RRSIGs over DS RRset
RRSIG=5613 and DNSKEY=5613 verifies the DS RRset
Found 3 DNSKEY records for stream
DS=31735/SHA-256 verifies DNSKEY=31735/SEP
Found 2 RRSIGs over DNSKEY RRset
RRSIG=31686 and DNSKEY=31686 verifies the DNSKEY RRset
ippacket.stream
Found 1 DS records for ippacket.stream in the stream zone
DS=65045/SHA-256 has algorithm RSASHA256
Found 1 RRSIGs over DS RRset
RRSIG=31686 and DNSKEY=31686 verifies the DS RRset
Found 1 DNSKEY records for ippacket.stream
DS=65045/SHA-256 verifies DNSKEY=65045/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=65045 and DNSKEY=65045/SEP verifies the DNSKEY RRset
ns1.ippacket.stream is authoritative for sigfail.rsa2048-sha256.ippacket.stream
rsa2048-sha256.ippacket.stream
Found 1 DS records for rsa2048-sha256.ippacket.stream in the ippacket.stream zone
DS=46436/SHA-256 has algorithm RSASHA256
Found 1 RRSIGs over DS RRset
RRSIG=65045 and DNSKEY=65045/SEP verifies the DS RRset
Found 1 DNSKEY records for rsa2048-sha256.ippacket.stream
DS=46436/SHA-256 verifies DNSKEY=46436/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=46436 and DNSKEY=46436/SEP verifies the DNSKEY RRset
ns1.ippacket.stream is authoritative for sigfail.rsa2048-sha256.ippacket.stream
sigfail.rsa2048-sha256.ippacket.stream A RR has value 195.201.14.36
Found 1 RRSIGs over A RRset
RRSIG=46436 and DNSKEY=46436/SEP does not verify the A RRset (signature verification failed)
None of the 1 RRSIG and 1 DNSKEY records validate the A RRset
The A RRset was not signed by any trusted keys

Move your mouse over any or symbols for remediation hints.

Want a second opinion? Test sigfail.verteiltesysteme.net at dnsviz.net.

DNSSEC Debugger

↓ Advanced options