Back to Verisign Labs Tools
Domain Name: Detail: more(+) / less(-) Time: 2024-02-21 09:41:17 UTC

Analyzing DNSSEC problems for adf.gov

.
Found 2 DNSKEY records for .
DS=20326/SHA-256 verifies DNSKEY=20326/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=20326 and DNSKEY=20326/SEP verifies the DNSKEY RRset
gov
Found 1 DS records for gov in the . zone
DS=64280/SHA-256 has algorithm RSASHA256
Found 1 RRSIGs over DS RRset
RRSIG=30903 and DNSKEY=30903 verifies the DS RRset
Found 3 DNSKEY records for gov
DS=64280/SHA-256 verifies DNSKEY=64280/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=64280 and DNSKEY=64280/SEP verifies the DNSKEY RRset
adf.gov
Found 5 DS records for adf.gov in the gov zone
DS=16281/SHA-1 uses a deprecated digest algorithm
DS=51142/SHA-1 uses a deprecated digest algorithm
DS=16281/SHA-1 has algorithm RSASHA1-NSEC3-SHA1
DS=16281/SHA-256 has algorithm RSASHA1-NSEC3-SHA1
DS=51142/SHA-1 has algorithm RSASHA1
DS=51142/SHA-256 has algorithm RSASHA1
DS=56043/SHA-256 has algorithm RSASHA1-NSEC3-SHA1
Found 1 RRSIGs over DS RRset
RRSIG=10104 and DNSKEY=10104 verifies the DS RRset
Found 5 DNSKEY records for adf.gov
None of the 5 DNSKEY records could be validated by any of the 5 DS records
Found 2 RRSIGs over DNSKEY RRset
RRSIG=2072 and DNSKEY=2072 verifies the DNSKEY RRset
The DNSKEY RRset was not signed by any trusted keys
auth120.ns.uu.net is authoritative for adf.gov
adf.gov A RR has value 3.221.42.84
Found 1 RRSIGs over A RRset
RRSIG=2072 and DNSKEY=2072 verifies the A RRset
adf.gov
auth111.ns.uu.net is authoritative for adf.gov
adf.gov A RR has value 3.221.42.84
Found 1 RRSIGs over A RRset
RRSIG=2072 and DNSKEY=2072 verifies the A RRset

Move your mouse over any or symbols for remediation hints.

Want a second opinion? Test adf.gov at dnsviz.net.

DNSSEC Debugger

↓ Advanced options