Back to Verisign Labs Tools
Domain Name: Detail: more(+) / less(-) Time: 2019-02-21 07:22:02 UTC, NTP stratum 4

Analyzing DNSSEC problems for UNNPP.GOV

Found 3 DNSKEY records for .
DS=20326/SHA-256 verifies DNSKEY=20326/SEP
Found 2 RRSIGs over DNSKEY RRset
RRSIG=20326 and DNSKEY=20326/SEP verifies the DNSKEY RRset
Found 2 DS records for GOV in the . zone
DS=7698/SHA-1 has algorithm RSASHA256
DS=7698/SHA-256 has algorithm RSASHA256
Found 1 RRSIGs over DS RRset
RRSIG=16749 and DNSKEY=16749 verifies the DS RRset
Found 2 DNSKEY records for GOV
DS=7698/SHA-1 verifies DNSKEY=7698/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=7698 and DNSKEY=7698/SEP verifies the DNSKEY RRset
Found 4 DS records for UNNPP.GOV in the GOV zone
DS=8935/SHA-1 has algorithm RSASHA1-NSEC3-SHA1
DS=8935/SHA-256 has algorithm RSASHA1-NSEC3-SHA1
DS=51109/SHA-1 has algorithm RSASHA1-NSEC3-SHA1
DS=51109/SHA-256 has algorithm RSASHA1-NSEC3-SHA1
Found 1 RRSIGs over DS RRset
RRSIG=28157 and DNSKEY=28157 verifies the DS RRset
Found 4 DNSKEY records for UNNPP.GOV
DS=51109/SHA-1 verifies DNSKEY=51109/SEP
DS=8935/SHA-1 verifies DNSKEY=8935/SEP
Found 2 RRSIGs over DNSKEY RRset
RRSIG=21305 is expired
RRSIG=51109 is expired
None of the 2 RRSIG and 4 DNSKEY records validate the DNSKEY RRset
The DNSKEY RRset was not signed by any keys in the chain-of-trust serial (1528) differs from serial (1542)
Found 1 RRSIGs over SOA RRset
RRSIG=21305 and DNSKEY=21305 verifies the SOA RRset

Move your mouse over any or symbols for remediation hints.

Want a second opinion? Test UNNPP.GOV at

DNSSEC Analyzer

↓ Advanced options