Back to Verisign Labs Tools
Domain Name: Detail: more(+) / less(-) Time: 2024-04-25 16:01:26 UTC

Analyzing DNSSEC problems for xn--l1acc

.
Found 2 DNSKEY records for .
DS=20326/SHA-256 verifies DNSKEY=20326/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=20326 and DNSKEY=20326/SEP verifies the DNSKEY RRset
xn--l1acc
Found 2 DS records for xn--l1acc in the . zone
DS=45112/SHA-1 uses a deprecated digest algorithm
DS=45112/SHA-1 has algorithm RSASHA1
DS=45112/SHA-256 has algorithm RSASHA1
Found 1 RRSIGs over DS RRset
RRSIG=5613 and DNSKEY=5613 verifies the DS RRset
Found 2 DNSKEY records for xn--l1acc
DS=45112/SHA-1 verifies DNSKEY=45112/SEP
Found 2 RRSIGs over DNSKEY RRset
RRSIG=24771 and DNSKEY=24771 verifies the DNSKEY RRset
ns2.idn.mn is authoritative for xn--l1acc
xn--l1acc A RR has value 218.100.84.27
Found 1 RRSIGs over A RRset
RRSIG=24771 and DNSKEY=24771 verifies the A RRset
xn--l1acc
ns1.idn.mn is authoritative for xn--l1acc
xn--l1acc A RR has value 218.100.84.27
Found 1 RRSIGs over A RRset
RRSIG=24771 and DNSKEY=24771 verifies the A RRset
xn--l1acc
ns3.idn.mn is authoritative for xn--l1acc
xn--l1acc A RR has value 202.131.4.60
Found 1 RRSIGs over A RRset
RRSIG=24771 and DNSKEY=24771 verifies the A RRset

Move your mouse over any or symbols for remediation hints.

Want a second opinion? Test xn--l1acc at dnsviz.net.

DNSSEC Debugger

↓ Advanced options