Total Tests
42
Passed
31
Critical Issues
4
Your domain uses multiple DNS providers (NS1 and DNS Provider) with the following distribution: 4 nameservers from NS1, 2 nameservers from DNS Provider. This multi-provider setup increases DNS redundancy and geographical distribution, though it requires careful management to maintain consistency across all providers.
Information provided by k.gtld-servers.net
198.51.44.12620:4d:4000:6259:7:1:0:1198.51.45.12a00:edc0:6259:7:1::2198.51.44.652620:4d:4000:6259:7:1:0:3198.51.45.652a00:edc0:6259:7:1::4204.74.104.512610:a1:3133::53204.74.106.512610:a1:3233::53Note:
The parent server is providing glue records for these nameservers. While not required (since the nameservers are not under your domain), this helps optimize DNS resolution.
| Status | Test name | Information |
|---|---|---|
Authoritative Nameservers | These nameservers are responsible for answering queries about your domain 6 Records dns1.p01.nsone.netdns2.p01.nsone.netdns3.p01.nsone.netdns4.p01.nsone.netns51.ultradns2.comns51.ultradns2.orgDNS Provider ConfigurationYour domain uses multiple DNS providers (NS1 and DNS Provider) with the following distribution: 4 nameservers from NS1, 2 nameservers from DNS Provider. This multi-provider setup increases DNS redundancy and geographical distribution, though it requires careful management to maintain consistency across all providers. Source: This information was kindly provided by k.gtld-servers.net ๐๐ผ | |
TLD Delegation Check | Good. k.gtld-servers.net has information for your TLD. This confirms your domain is properly delegated. | |
Nameservers Listed at Parent | Warning: Mismatch between parent nameservers and actual NS records.
Parent-only nameservers (listed at parent but not in NS records):
โข ns51.ultradns2.com
โข ns51.ultradns2.org
NS-only nameservers (in NS records but not listed at parent):
โข pdns5.ultradns.info
โข pdns1.ultradns.net
โข pdns3.ultradns.org
This inconsistency can cause DNS resolution issues and should be resolved by updating either the parent nameservers or the NS records. | |
Glue Records from Parent | Glue Records from Parent ServerInformation provided by k.gtld-servers.net dns1.p01.nsone.netNameserver IPv4 Addresses: 198.51.44.1IPv6 Addresses: 2620:4d:4000:6259:7:1:0:1dns2.p01.nsone.netNameserver IPv4 Addresses: 198.51.45.1IPv6 Addresses: 2a00:edc0:6259:7:1::2dns3.p01.nsone.netNameserver IPv4 Addresses: 198.51.44.65IPv6 Addresses: 2620:4d:4000:6259:7:1:0:3dns4.p01.nsone.netNameserver IPv4 Addresses: 198.51.45.65IPv6 Addresses: 2a00:edc0:6259:7:1::4ns51.ultradns2.comNameserver IPv4 Addresses: 204.74.104.51IPv6 Addresses: 2610:a1:3133::53ns51.ultradns2.orgNameserver IPv4 Addresses: 204.74.106.51IPv6 Addresses: 2610:a1:3233::53Note: The parent server is providing glue records for these nameservers. While not required (since the nameservers are not under your domain), this helps optimize DNS resolution. |
| Status | Test name | Information |
|---|---|---|
Nameserver Records from Zone | dns1.p01.nsone.netNS1 IPv4 Addresses 198.51.44.1 IPv6 Addresses 2620:4d:4000:6259:7:1:0:1 Authoritative Non-Recursive TCP UDP TTL: 172,800s (2 days) dns2.p01.nsone.netNS1 IPv4 Addresses 198.51.45.1 IPv6 Addresses 2a00:edc0:6259:7:1::2 Authoritative Non-Recursive TCP UDP TTL: 172,800s (2 days) dns3.p01.nsone.netNS1 IPv4 Addresses 198.51.44.65 IPv6 Addresses 2620:4d:4000:6259:7:1:0:3 Authoritative Non-Recursive TCP UDP TTL: 172,800s (2 days) dns4.p01.nsone.netNS1 IPv4 Addresses 198.51.45.65 IPv6 Addresses 2a00:edc0:6259:7:1::4 Authoritative Non-Recursive TCP UDP TTL: 172,800s (2 days) pdns1.ultradns.netUltraDNS / Neustar IPv4 Addresses 204.74.108.1 IPv6 Addresses 2001:502:f3ff::1 Authoritative Non-Recursive TCP UDP TTL: 172,800s (2 days) pdns3.ultradns.orgUltraDNS / Neustar IPv4 Addresses 199.7.68.1 IPv6 Addresses 2610:a1:1015::1 Authoritative Non-Recursive TCP UDP TTL: 172,800s (2 days) pdns5.ultradns.infoIPv4 Addresses 204.74.114.1 IPv6 Addresses 2610:a1:1016::1 Authoritative Non-Recursive TCP UDP TTL: 172,800s (2 days) | |
Open Recursive Queries | Good. No nameservers allow recursive queries. | |
Glue Record Consistency | Warning: Mismatched both IPv4 and IPv6 records between parent and nameserver responses. This can cause inconsistent DNS resolution.
Mismatches found:
โข pdns5.ultradns.info:
IPv4: Parent has [], Nameserver has [204.74.114.1]
IPv6: Parent has [], Nameserver has [2610:a1:1016::1]
โข pdns1.ultradns.net:
IPv4: Parent has [], Nameserver has [204.74.108.1]
IPv6: Parent has [], Nameserver has [2001:502:f3ff::1]
โข pdns3.ultradns.org:
IPv4: Parent has [], Nameserver has [199.7.68.1]
IPv6: Parent has [], Nameserver has [2610:a1:1015::1] | |
Missing Glue for NS Records | Note: Your nameservers are not under your domain, so additional glue records are not required. | |
Mismatched NS records | Good. The NS records at all your nameservers are identical. | |
DNS servers responded | Good. All nameservers listed at the parent server responded. | |
Name of nameservers are valid | All NS records appear to be valid hostnames. | |
Nameserver Redundancy Check | You have 7 nameservers. This meets the minimum requirement, though RFC2182 section 5 recommends at least 3 for better reliability. | |
Lame Delegation Check | Good. All nameservers are answering authoritatively for your domain. | |
Parent Missing Nameservers | Error: The following nameservers are missing from parent zone:
pdns5.ultradns.info
pdns1.ultradns.net
pdns3.ultradns.org
This inconsistency can cause DNS resolution problems. See RFC1034 section 3.6 for proper delegation requirements. | |
Zone Missing Nameservers | Error: The following nameservers from parent are missing in your zone:
ns51.ultradns2.com
ns51.ultradns2.org
This means some nameservers registered at the parent are not configured in your zone. See RFC1034 section 3.6 for proper delegation requirements. | |
CNAMEs at Apex Check | Good. No CNAME records found for NS records, as per RFC1912 section 2.4 and RFC2181 section 10.3. | |
NS IP Subnet Diversity | Found 7 pair(s) of nameserver IPs in the same /16 subnet. For better redundancy, consider using nameservers on different subnets as recommended by RFC2182 section 5. Affected pairs: 204.74.114.1 and 204.74.108.1, 198.51.44.1 and 198.51.45.1, 198.51.44.1 and 198.51.44.65, 198.51.44.1 and 198.51.45.65, 198.51.45.1 and 198.51.44.65, 198.51.45.1 and 198.51.45.65, 198.51.44.65 and 198.51.45.65. Note: providers using anycast may have geographic redundancy despite shared subnets. | |
NS IP Public Accessibility | Good. All nameserver IPs (both IPv4 and IPv6) are public, ensuring global accessibility as required by RFC1035. | |
DNS servers allow TCP connection | Good. All DNS servers allow TCP connections, which is required for larger DNS responses as per RFC1035. | |
DNS servers allow UDP connection | Good. All DNS servers allow UDP connections, which is required for standard DNS queries. | |
NS AS Diversity Check | Good. Your nameservers appear to be on different networks, providing better redundancy. | |
Stealth Nameserver Check | Warning: Found stealth nameservers:
Nameservers in zone but missing from parent:
โข pdns5.ultradns.info
โข pdns1.ultradns.net
โข pdns3.ultradns.org
Nameservers in parent but missing from zone:
โข ns51.ultradns2.com
โข ns51.ultradns2.org
Stealth nameservers can cause inconsistent DNS resolution and should be either properly registered at both parent and zone, or removed. |
Serial Number
2013093317
A unique version number that changes whenever the zone file is updated
How often secondary nameservers check for updates (20m - 24h)
How long to wait before retrying a failed zone transfer (2m - 2h)
How long secondary servers serve stale zone data (1w - 4w)
Default time-to-live for resource records (5m - 24h)
| Status | Test name | Information |
|---|---|---|
SOA record | Primary Nameserverdns1.p01.nsone.net Hostmaster Emaildnsmaster.bloomberg.com Serial Number 2013093317 Non-Standard (Unix Timestamp) A unique version number that changes whenever the zone file is updated Time IntervalsRefresh43200 seconds (12 hours) How often secondary nameservers check for updates (20m - 24h) Retry3600 seconds (1 hours) How long to wait before retrying a failed zone transfer (2m - 2h) Expire3600000 seconds (41 days) How long secondary servers serve stale zone data (1w - 4w) TTL14400 seconds (4 hours) Default time-to-live for resource records (5m - 24h) | |
SOA Serial Consistency | SOA Serial numbers per nameserver:
pdns5.ultradns.info: 2013093317
dns1.p01.nsone.net: 2013093317
dns2.p01.nsone.net: 2013093317
dns3.p01.nsone.net: 2013093317
dns4.p01.nsone.net: 2013093317
pdns1.ultradns.net: 2013093317
pdns3.ultradns.org: 2013093317
Good. All nameservers report the same SOA serial number. | |
SOA MNAME entry | OK. dns1.p01.nsone.net is correctly listed as one of your nameservers. | |
SOA Serial | Your SOA serial number is: 2013093317. | |
SOA REFRESH | OK. Your SOA REFRESH interval is: 43200 seconds (720 minutes). This is within the recommended range of 1200-43200 seconds as per RFC1912 section 2.2. | |
SOA RETRY | OK. Your SOA RETRY value is: 3600 seconds (60 minutes). This is within the recommended range of 120-7200 seconds as per RFC1912 section 2.2. | |
SOA EXPIRE | Current expire time is 3600000 seconds (41 days).
Warning: Common practice recommends a maximum of 28 days (2419200 seconds) to avoid stale data being served for too long. | |
SOA MINIMUM TTL | OK. Your SOA MINIMUM TTL is: 14400 seconds (240 minutes). This value is used for negative caching and is within the recommended range of 180-86400 seconds as per RFC2308 section 4. |
Multiple IPv4 addresses configured for redundancy and load balancing
15.197.146.1563.33.146.110Configuration Benefits
DNS-based load balancing
Distributes traffic across multiple servers to improve performance and reliability
Failover capability
Automatic fallback to healthy servers if one becomes unavailable
Geographic distribution potential
Ability to serve content from servers closest to users
| Status | Test name | Information |
|---|---|---|
A Record Configuration | IPv4 ConfigurationMultiple IPv4 addresses configured for redundancy and load balancing IPv4 Addresses 15.197.146.1563.33.146.110Configuration Benefits DNS-based load balancing Distributes traffic across multiple servers to improve performance and reliability Failover capability Automatic fallback to healthy servers if one becomes unavailable Geographic distribution potential Ability to serve content from servers closest to users TTL: 18880s Provides a good balance between propagation speed and DNS load | |
A Record TTL | TTL of 18880 seconds provides a good balance between propagation speed and DNS load. |
| Status | Test name | Information |
|---|---|---|
IPv6 Support | No AAAA (IPv6) records found. While not required, IPv6 support is recommended for future-proofing your domain and improving accessibility for IPv6 users. |
| Priority | Mail Server | Actions |
|---|---|---|
0 | mgcny1.bloomberg.com | |
0 | mgcny2.bloomberg.com | |
0 | mgcnj1.bloomberg.com | |
0 | mgcnj2.bloomberg.com |
| PTR Query | Hostname |
|---|---|
16.169.172.199.in-addr.arpa | mgcny1.bloomberg.com |
48.169.172.199.in-addr.arpa | mgcny2.bloomberg.com |
21.241.191.69.in-addr.arpa | mgcnj1.bloomberg.com |
34.241.191.69.in-addr.arpa | mgcnj2.bloomberg.com |
| Status | Test name | Information | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Mail Server Consistency | All nameservers are reporting the same mail server configuration. This consistency ensures reliable email delivery. | ||||||||||||||||
Mail Server Configuration | Mail Exchange Configuration
| ||||||||||||||||
Mail Server Hostname Validation | All mail server hostnames are properly formatted. | ||||||||||||||||
Public IP Validation | All mail servers use public IP addresses, ensuring global email delivery. | ||||||||||||||||
CNAME Validation | Mail servers are properly configured without CNAME records. | ||||||||||||||||
IP Uniqueness | Each mail server has unique IP addresses, indicating proper distribution of mail handling. | ||||||||||||||||
Reverse DNS Records | Reverse DNS RecordsAll Valid
Proper reverse DNS records are essential for email deliverability. Mail servers often check if sending IPs have matching PTR records. |
| Status | Test name | Information |
|---|---|---|
WWW Configuration | No WWW record found |
| Status | Test name | Information |
|---|---|---|
DNSSEC | DNSSEC validation failed. This indicates a problem with your DNSSEC configuration:
โข DNSKEY query failed with SERVFAIL
โข DS query failed with SERVFAIL
Please check your DNSSEC configuration with your DNS provider. | |
Zone Transfer | Nameserver provider UltraDNS is known to block zone transfers (AXFR). No test needed.
Learn more: https://dnschkr.com/blog/dns-attacks-guide#dns-zone-transfer-attack-axfr | |
Wildcard DNS | Good. Tested notrealdnschkr.bloomberg.com - No wildcard DNS records found, ensuring random subdomains won't resolve to an IP address. | |
NXDOMAIN Response | Warning: Server does not return NXDOMAIN for non-existent domains. This could indicate misconfiguration or intentional wildcard records. | |
CAA Records | Found CAA records:
โโ iodef: mailto:[email protected]
โโ issue: amazon.com
โโ issue: digicert.com
โโ issuewild: digicert.com
These records control which Certificate Authorities can issue certificates for your domain. | |
Subdomain Takeover | Found 1 subdomain with dangling CNAME records โ potential subdomain takeover risk:
โโ staging.bloomberg.com โ staging.www.bloomberg.com (target does not resolve)
An attacker could register the target service and take control of these subdomains. Remove the CNAME records or point them to active services.
Learn more: https://dnschkr.com/blog/dns-attacks-guide#subdomain-takeover |
google-site-verification | vH_zs-JrwvXxkyuUqmeN9t3iMYZqyt1-BJUsoyN3ca8 |
extensis-domain-verification | 707df5b4-0868-499f-af75-51718e082698 |
OSSRH-64276 | N/A |
google-site-verification | vH_zs-JrwvXxkyuUqmeN9t3iMYZqyt1-BJUsoyN3ca8 |
MS | ms33692690 |
google-site-verification | ClT3QBQ-Rd4b3AAq2gmQ-u_94EliZRmC2e-Kb4t9zEo |
| Status | Test name | Information | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|
TXT Records | Click any row to copy the raw value
Showing 3 of 20 records (limited view) | |||||||||
SPF Record | Found SPF record: v=spf1 ip4:69.184.0.0/13 ip4:199.172.169.0/24 ip4:208.22.56.0/24 ip4:69.191.241.124 -all | |||||||||
DMARC Record | No DMARC record found. DMARC helps prevent email spoofing and provides reporting capabilities. Consider adding a DMARC record to improve email security. | |||||||||
Domain Verification | Click any row to copy the raw value
Showing 3 of 5 records (limited view) |