Back to Verisign Labs Tools
Domain Name: Detail: more(+) / less(-) Time: 2017-11-22 22:14:51 UTC, NTP stratum 4

Analyzing DNSSEC problems for xn--l1acc

Found 3 DNSKEY records for .
DS=19036/SHA-256 verifies DNSKEY=19036/SEP
DS=20326/SHA-256 verifies DNSKEY=20326/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=19036 and DNSKEY=19036/SEP verifies the DNSKEY RRset
Found 2 DS records for xn--l1acc in the . zone
DS=45112/SHA-256 has algorithm RSASHA1
DS=45112/SHA-1 has algorithm RSASHA1
Found 1 RRSIGs over DS RRset
RRSIG=46809 and DNSKEY=46809 verifies the DS RRset
Found 2 DNSKEY records for xn--l1acc
DS=45112/SHA-256 verifies DNSKEY=45112/SEP
Found 2 RRSIGs over DNSKEY RRset
RRSIG=24771 and DNSKEY=24771 verifies the DNSKEY RRset
All Queries to for xn--l1acc/SOA timed out or failed
xn--l1acc A RR has value
Found 1 RRSIGs over A RRset
RRSIG=24771 and DNSKEY=24771 verifies the A RRset

Move your mouse over any or symbols for remediation hints.

Want a second opinion? Test xn--l1acc at

DNSSEC Analyzer

↓ Advanced options