Back to Verisign Labs Tools
Domain Name: Detail: more(+) / less(-) Time: 2020-01-18 11:21:00 UTC, NTP stratum 4

Analyzing DNSSEC problems for CANCER.GOV

Found 2 DNSKEY records for .
DS=20326/SHA-256 verifies DNSKEY=20326/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=20326 and DNSKEY=20326/SEP verifies the DNSKEY RRset
Found 2 DS records for GOV in the . zone
DS=7698/SHA-1 has algorithm RSASHA256
DS=7698/SHA-256 has algorithm RSASHA256
Found 1 RRSIGs over DS RRset
RRSIG=33853 and DNSKEY=33853 verifies the DS RRset
Found 3 DNSKEY records for GOV
DS=7698/SHA-1 verifies DNSKEY=7698/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=7698 and DNSKEY=7698/SEP verifies the DNSKEY RRset
Found 4 DS records for CANCER.GOV in the GOV zone
DS=18960/SHA-256 has algorithm RSASHA1-NSEC3-SHA1
DS=33678/SHA-256 has algorithm RSASHA1-NSEC3-SHA1
DS=18960/SHA-1 has algorithm RSASHA1-NSEC3-SHA1
DS=33678/SHA-1 has algorithm RSASHA1-NSEC3-SHA1
Found 1 RRSIGs over DS RRset
RRSIG=36558 and DNSKEY=36558 verifies the DS RRset
Found 3 DNSKEY records for CANCER.GOV
DS=18960/SHA-256 verifies DNSKEY=18960/SEP
DS=33678/SHA-256 verifies DNSKEY=33678/SEP
Found 3 RRSIGs over DNSKEY RRset
RRSIG=18960 and DNSKEY=18960/SEP verifies the DNSKEY RRset
All Queries to ns3.nih.GOV for CANCER.GOV/SOA timed out or failed
CANCER.GOV A RR has value
Found 1 RRSIGs over A RRset
RRSIG=49760 and DNSKEY=49760 verifies the A RRset

Move your mouse over any or symbols for remediation hints.

Want a second opinion? Test CANCER.GOV at

DNSSEC Analyzer

↓ Advanced options