Back to Verisign Labs Tools
Domain Name: Detail: more(+) / less(-) Time: 2019-02-21 02:20:31 UTC, NTP stratum 4

Analyzing DNSSEC problems for IAD.GOV

.
Found 3 DNSKEY records for .
DS=20326/SHA-256 verifies DNSKEY=20326/SEP
Found 2 RRSIGs over DNSKEY RRset
RRSIG=20326 and DNSKEY=20326/SEP verifies the DNSKEY RRset
GOV
Found 2 DS records for GOV in the . zone
DS=7698/SHA-1 has algorithm RSASHA256
DS=7698/SHA-256 has algorithm RSASHA256
Found 1 RRSIGs over DS RRset
RRSIG=16749 and DNSKEY=16749 verifies the DS RRset
Found 2 DNSKEY records for GOV
DS=7698/SHA-1 verifies DNSKEY=7698/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=7698 and DNSKEY=7698/SEP verifies the DNSKEY RRset
IAD.GOV
Found 4 DS records for IAD.GOV in the GOV zone
DS=8800/SHA-1 has algorithm RSASHA256
DS=8800/SHA-256 has algorithm RSASHA256
DS=27866/SHA-1 has algorithm RSASHA256
DS=27866/SHA-256 has algorithm RSASHA256
Found 1 RRSIGs over DS RRset
RRSIG=28157 and DNSKEY=28157 verifies the DS RRset
Found 4 DNSKEY records for IAD.GOV
DS=27866/SHA-1 verifies DNSKEY=27866/SEP
DS=8800/SHA-1 verifies DNSKEY=8800/SEP
Found 4 RRSIGs over DNSKEY RRset
RRSIG=8800 is expired
RRSIG=46698 is expired
RRSIG=8800 and DNSKEY=8800/SEP does not verify the DNSKEY RRset (signature verification failed)
RRSIG=46698 and DNSKEY=46698 does not verify the DNSKEY RRset (signature verification failed)
None of the 4 RRSIG and 4 DNSKEY records validate the DNSKEY RRset
The DNSKEY RRset was not signed by any keys in the chain-of-trust
IAD.GOV A RR has value 8.44.96.42
Found 2 RRSIGs over A RRset
RRSIG=46698 is expired
RRSIG=46698 and DNSKEY=46698 verifies the A RRset

Move your mouse over any or symbols for remediation hints.

Want a second opinion? Test IAD.GOV at dnsviz.net.

DNSSEC Analyzer

↓ Advanced options