Back to Verisign Labs Tools
Domain Name: Detail: more(+) / less(-) Time: 2025-01-20 19:30:40 UTC

Analyzing DNSSEC problems for dcma.mil

.
Found 3 DNSKEY records for .
DS=20326/SHA-256 verifies DNSKEY=20326/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=20326 and DNSKEY=20326/SEP verifies the DNSKEY RRset
mil
Found 1 DS records for mil in the . zone
DS=63500/SHA-256 has algorithm RSASHA256
Found 1 RRSIGs over DS RRset
RRSIG=26470 and DNSKEY=26470 verifies the DS RRset
Found 3 DNSKEY records for mil
DS=63500/SHA-256 verifies DNSKEY=63500/SEP
Found 2 RRSIGs over DNSKEY RRset
RRSIG=10729 and DNSKEY=10729 verifies the DNSKEY RRset
dcma.mil
Found 2 DS records for dcma.mil in the mil zone
DS=32074/SHA-1 uses a deprecated digest algorithm
DS=32074/SHA-256 has algorithm RSASHA256
DS=32074/SHA-1 has algorithm RSASHA256
Found 1 RRSIGs over DS RRset
RRSIG=10729 and DNSKEY=10729 verifies the DS RRset
Found 2 DNSKEY records for dcma.mil
DS=32074/SHA-256 verifies DNSKEY=32074/SEP
Found 2 RRSIGs over DNSKEY RRset
RRSIG=3165 and DNSKEY=3165 verifies the DNSKEY RRset
NS4.DCMA.MIL is authoritative for dcma.mil
Found 1 RRSIGs over SOA RRset
RRSIG=3165 and DNSKEY=3165 verifies the SOA RRset
dcma.mil
NS3.DCMA.MIL is authoritative for dcma.mil
Found 1 RRSIGs over SOA RRset
RRSIG=3165 and DNSKEY=3165 verifies the SOA RRset

Move your mouse over any or symbols for remediation hints.

Want a second opinion? Test dcma.mil at dnsviz.net.

DNSSEC Debugger

↓ Advanced options