Back to Verisign Labs Tools
Domain Name: Detail: more(+) / less(-) Time: 2025-02-15 10:33:21 UTC

Analyzing DNSSEC problems for 0.0.0.9.0.4.2.ip6.arpa

.
Found 3 DNSKEY records for .
DS=20326/SHA-256 verifies DNSKEY=20326/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=20326 and DNSKEY=20326/SEP verifies the DNSKEY RRset
arpa
Found 1 DS records for arpa in the . zone
DS=42581/SHA-256 has algorithm RSASHA256
Found 1 RRSIGs over DS RRset
RRSIG=26470 and DNSKEY=26470 verifies the DS RRset
Found 2 DNSKEY records for arpa
DS=42581/SHA-256 verifies DNSKEY=42581/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=42581 and DNSKEY=42581/SEP verifies the DNSKEY RRset
ip6.arpa
Found 3 DS records for ip6.arpa in the arpa zone
DS=13880/SHA-256 has algorithm RSASHA256
DS=45094/SHA-256 has algorithm RSASHA256
DS=64060/SHA-256 has algorithm RSASHA256
Found 1 RRSIGs over DS RRset
RRSIG=41220 and DNSKEY=41220 verifies the DS RRset
Found 3 DNSKEY records for ip6.arpa
DS=64060/SHA-256 verifies DNSKEY=64060/SEP
Found 2 RRSIGs over DNSKEY RRset
RRSIG=21619 and DNSKEY=21619/SEP verifies the DNSKEY RRset
0.4.2.ip6.arpa
Found 1 DS records for 0.4.2.ip6.arpa in the ip6.arpa zone
DS=15415/SHA-256 has algorithm ECDSAP256SHA256
Found 1 RRSIGs over DS RRset
RRSIG=65256 and DNSKEY=65256 verifies the DS RRset
Found 2 DNSKEY records for 0.4.2.ip6.arpa
DS=15415/SHA-256 verifies DNSKEY=15415/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=15415 and DNSKEY=15415/SEP verifies the DNSKEY RRset
0.0.0.9.0.4.2.ip6.arpa
Found 2 DS records for 0.0.0.9.0.4.2.ip6.arpa in the 0.4.2.ip6.arpa zone
DS=51978/SHA-1 uses a deprecated digest algorithm
DS=51978/SHA-256 has algorithm RSASHA512
DS=51978/SHA-1 has algorithm RSASHA512
Found 1 RRSIGs over DS RRset
RRSIG=14045 and DNSKEY=14045 verifies the DS RRset
Found 1 DNSKEY records for 0.0.0.9.0.4.2.ip6.arpa
None of the 1 DNSKEY records could be validated by any of the 2 DS records
Found 1 RRSIGs over DNSKEY RRset
RRSIG=9842 and DNSKEY=9842/SEP verifies the DNSKEY RRset
The DNSKEY RRset was not signed by any trusted keys
All Queries to ns1.nkn.in for 0.0.0.9.0.4.2.ip6.arpa/A timed out or failed
ns2.nkn.in returns REFUSED for 0.0.0.9.0.4.2.ip6.arpa/A
ns6.nkn.in is authoritative for 0.0.0.9.0.4.2.ip6.arpa
Found 1 RRSIGs over NSEC RRset
RRSIG=9842 and DNSKEY=9842/SEP verifies the NSEC RRset
NSEC proves no records of type A exist for 0.0.0.9.0.4.2.ip6.arpa
Found 1 RRSIGs over SOA RRset
RRSIG=9842 and DNSKEY=9842/SEP verifies the SOA RRset
0.0.0.9.0.4.2.ip6.arpa
No response from 0.0.0.9.0.4.2.ip6.arpa nameservers

Move your mouse over any or symbols for remediation hints.

Want a second opinion? Test 0.0.0.9.0.4.2.ip6.arpa at dnsviz.net.

DNSSEC Debugger

↓ Advanced options