Back to Verisign Labs Tools
Domain Name: Detail: more(+) / less(-) Time: 2025-07-01 01:18:09 UTC

Analyzing DNSSEC problems for dtra.mil

.
Found 4 DNSKEY records for .
DS=20326/SHA-256 verifies DNSKEY=20326/SEP
Found 1 RRSIGs over DNSKEY RRset
RRSIG=20326 and DNSKEY=20326/SEP verifies the DNSKEY RRset
mil
Found 1 DS records for mil in the . zone
DS=63500/SHA-256 has algorithm RSASHA256
Found 1 RRSIGs over DS RRset
RRSIG=53148 and DNSKEY=53148 verifies the DS RRset
Found 3 DNSKEY records for mil
DS=63500/SHA-256 verifies DNSKEY=63500/SEP
Found 2 RRSIGs over DNSKEY RRset
RRSIG=14128 and DNSKEY=14128 verifies the DNSKEY RRset
dtra.mil
Found 2 DS records for dtra.mil in the mil zone
DS=52765/SHA-1 uses a deprecated digest algorithm
DS=52765/SHA-1 has algorithm RSASHA256
DS=52765/SHA-256 has algorithm RSASHA256
Found 1 RRSIGs over DS RRset
RRSIG=14128 and DNSKEY=14128 verifies the DS RRset
Found 3 DNSKEY records for dtra.mil
DS=52765/SHA-1 verifies DNSKEY=52765/SEP
Found 3 RRSIGs over DNSKEY RRset
RRSIG=15262 and DNSKEY=15262/SEP verifies the DNSKEY RRset
NS1.DTRA.MIL is authoritative for dtra.mil
Found 1 RRSIGs over SOA RRset
RRSIG=27711 and DNSKEY=27711 verifies the SOA RRset
dtra.mil
NS2.DTRA.MIL is authoritative for dtra.mil
Found 1 RRSIGs over SOA RRset
RRSIG=27711 and DNSKEY=27711 verifies the SOA RRset

Move your mouse over any or symbols for remediation hints.

Want a second opinion? Test dtra.mil at dnsviz.net.

DNSSEC Debugger

↓ Advanced options