Back to Verisign Labs Tools
Domain Name: Detail: more(+) / less(-) Time: 2026-01-29 21:44:18 UTC

Analyzing DNSSEC problems for adr.gov

.
Found 3 DNSKEY records for .
DS=20326/SHA-256 verifies DNSKEY=20326/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=20326 and DNSKEY=20326/SEP verifies the DNSKEY RRset
gov
Found 1 DS records for gov in the . zone
DS=2536/SHA-256 has algorithm ECDSAP256SHA256
Found 1 RRSIGs over DS RRset
RRSIG=21831 and DNSKEY=21831 verifies the DS RRset
Found 2 DNSKEY records for gov
DS=2536/SHA-256 verifies DNSKEY=2536/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=2536 and DNSKEY=2536/SEP verifies the DNSKEY RRset
adr.gov
Found 1 DS records for adr.gov in the gov zone
DS=14962/SHA-256 has algorithm RSASHA256
Found 1 RRSIGs over DS RRset
RRSIG=35496 and DNSKEY=35496 verifies the DS RRset
Found 2 DNSKEY records for adr.gov
DS=14962/SHA-256 verifies DNSKEY=14962/SEP
Found 2 RRSIGs over DNSKEY RRset
RRSIG=14962 is expired
RRSIG=48009 is expired
None of the 2 RRSIG and 2 DNSKEY records validate the DNSKEY RRset
The DNSKEY RRset was not signed by any trusted keys
ctc-dns2.usa-ctc.com is authoritative for adr.gov
adr.gov A RR has value 3.32.69.55
Found 1 RRSIGs over A RRset
None of the 1 RRSIG and 2 DNSKEY records validate the A RRset
adr.gov
ctc-dns.usa-ctc.com is authoritative for adr.gov
adr.gov A RR has value 3.32.69.55
Found 1 RRSIGs over A RRset
RRSIG=48009 is expired
None of the 1 RRSIG and 2 DNSKEY records validate the A RRset

Move your mouse over any or symbols for remediation hints.

Want a second opinion? Test adr.gov at dnsviz.net.

DNSSEC Debugger

↓ Advanced options