Total Tests
30
Passed
30
Critical Issues
0
Your domain is using Amazon Route 53 DNS service, which provides a globally distributed network of nameservers for high availability and low latency.
Information provided by k.gtld-servers.net
205.251.194.752600:9000:5302:4b00::1205.251.193.122205.251.198.1162600:9000:5306:7400::1205.251.196.2182600:9000:5304:da00::1Note:
The parent server is providing glue records for these nameservers. While not required (since the nameservers are not under your domain), this helps optimize DNS resolution.
| Status | Test name | Information |
|---|---|---|
Authoritative Nameservers | These nameservers are responsible for answering queries about your domain 4 Records ns-587.awsdns-09.netns-378.awsdns-47.comns-1652.awsdns-14.co.ukns-1242.awsdns-27.orgAWS Route 53Your domain is using Amazon Route 53 DNS service, which provides a globally distributed network of nameservers for high availability and low latency. Source: This information was kindly provided by k.gtld-servers.net ๐๐ผ | |
TLD Delegation Check | Good. k.gtld-servers.net has information for your TLD. This confirms your domain is properly delegated. | |
Nameservers Listed at Parent | Good. The parent server has your nameservers listed and they match the actual NS records. This ensures consistent DNS resolution. | |
Glue Records from Parent | Glue Records from Parent ServerInformation provided by k.gtld-servers.net ns-587.awsdns-09.netNameserver IPv4 Addresses: 205.251.194.75IPv6 Addresses: 2600:9000:5302:4b00::1ns-378.awsdns-47.comNameserver IPv4 Addresses: 205.251.193.122ns-1652.awsdns-14.co.ukNameserver IPv4 Addresses: 205.251.198.116IPv6 Addresses: 2600:9000:5306:7400::1ns-1242.awsdns-27.orgNameserver IPv4 Addresses: 205.251.196.218IPv6 Addresses: 2600:9000:5304:da00::1Note: The parent server is providing glue records for these nameservers. While not required (since the nameservers are not under your domain), this helps optimize DNS resolution. |
| Status | Test name | Information |
|---|---|---|
Nameserver Records from Zone | ns-1242.awsdns-27.orgAWS Route 53 IPv4 Addresses 205.251.196.218 IPv6 Addresses 2600:9000:5304:da00::1 Authoritative Non-Recursive TCP UDP TTL: 172,800s (2 days) ns-1652.awsdns-14.co.ukAWS Route 53 IPv4 Addresses 205.251.198.116 IPv6 Addresses 2600:9000:5306:7400::1 Authoritative Non-Recursive TCP UDP TTL: 172,800s (2 days) ns-378.awsdns-47.comAWS Route 53 IPv4 Addresses 205.251.193.122 IPv6 Addresses 2600:9000:5301:7a00::1 Authoritative Non-Recursive TCP UDP TTL: 172,800s (2 days) ns-587.awsdns-09.netAWS Route 53 IPv4 Addresses 205.251.194.75 IPv6 Addresses 2600:9000:5302:4b00::1 Authoritative Non-Recursive TCP UDP TTL: 172,800s (2 days) | |
Open Recursive Queries | Good. No nameservers allow recursive queries. | |
Glue Record Consistency | Route 53's DNS uses a global network to speed up responses. Normally, the IP addresses at the parent nameservers and Route 53's servers should match. If they don't, it might just be a short-term update. | |
Missing Glue for NS Records | Route 53 manages glue records through their global DNS infrastructure. | |
Mismatched NS records | Good. The NS records at all your nameservers are identical. | |
DNS servers responded | Good. All nameservers listed at the parent server responded. | |
Name of nameservers are valid | All NS records appear to be valid hostnames. | |
Nameserver Redundancy Check | You have 4 nameservers. This meets the minimum requirement, though RFC2182 section 5 recommends at least 3 for better reliability. | |
Lame Delegation Check | Good. All nameservers are answering authoritatively for your domain. | |
Parent Missing Nameservers | Good. All NS records match between parent and nameservers, as required by RFC1034 section 3.6. | |
Zone Missing Nameservers | Good. All parent-listed nameservers are reported by your nameservers, as required by RFC1034 section 3.6. | |
CNAMEs at Apex Check | Good. No CNAME records found for NS records, as per RFC1912 section 2.4 and RFC2181 section 10.3. | |
NS IP Subnet Diversity | Anycast provider detected (AWS Route 53).While 6 IP pair(s) share a /16 prefix, AWS Route 53 distributes these across globally diverse datacenters using anycast routing. No subnet diversity concern per RFC2182 section 5. |
Serial Number
1
A unique version number that changes whenever the zone file is updated
How often secondary nameservers check for updates (20m - 24h)
How long to wait before retrying a failed zone transfer (2m - 2h)
How long secondary servers serve stale zone data (1w - 4w)
Default time-to-live for resource records (5m - 24h)
| Status | Test name | Information |
|---|---|---|
SOA record | Primary Nameserverns-1652.awsdns-14.co.uk Hostmaster Emailawsdns-hostmaster.amazon.com Serial Number 1 Non-Standard (Simple Counter) A unique version number that changes whenever the zone file is updated Time IntervalsRefresh7200 seconds (2 hours) How often secondary nameservers check for updates (20m - 24h) Retry900 seconds (15 minutes) How long to wait before retrying a failed zone transfer (2m - 2h) Expire1209600 seconds (14 days) How long secondary servers serve stale zone data (1w - 4w) TTL86400 seconds (1 days) Default time-to-live for resource records (5m - 24h) | |
SOA Serial Consistency | SOA Serial numbers per nameserver:
ns-1242.awsdns-27.org: 1
ns-1652.awsdns-14.co.uk: 1
ns-378.awsdns-47.com: 1
ns-587.awsdns-09.net: 1
Good. All nameservers report the same SOA serial number. | |
SOA MNAME entry | OK. ns-1652.awsdns-14.co.uk is correctly listed as one of your nameservers. | |
SOA Serial | Your SOA serial number is: 1. Using Amazon DNS automatic serial number management. | |
SOA REFRESH | OK. Your SOA REFRESH interval is: 7200 seconds (120 minutes). This is within the recommended range of 1200-43200 seconds as per RFC1912 section 2.2. | |
SOA RETRY | OK. Your SOA RETRY value is: 900 seconds (15 minutes). This is within the recommended range of 120-7200 seconds as per RFC1912 section 2.2. | |
SOA EXPIRE | Current expire time is 1209600 seconds (14 days). | |
SOA MINIMUM TTL | OK. Your SOA MINIMUM TTL is: 86400 seconds (1440 minutes). This value is used for negative caching and is within the recommended range of 180-86400 seconds as per RFC2308 section 4. |
Multiple IPv4 addresses configured for redundancy and load balancing
151.101.131.5151.101.3.5151.101.67.5151.101.195.5Configuration Benefits
DNS-based load balancing
Distributes traffic across multiple servers to improve performance and reliability
Failover capability
Automatic fallback to healthy servers if one becomes unavailable
Geographic distribution potential
Ability to serve content from servers closest to users
| Status | Test name | Information |
|---|---|---|
A Record Configuration | IPv4 ConfigurationMultiple IPv4 addresses configured for redundancy and load balancing IPv4 Addresses 151.101.131.5151.101.3.5151.101.67.5151.101.195.5Configuration Benefits DNS-based load balancing Distributes traffic across multiple servers to improve performance and reliability Failover capability Automatic fallback to healthy servers if one becomes unavailable Geographic distribution potential Ability to serve content from servers closest to users TTL: 21s Provides a good balance between propagation speed and DNS load | |
A Record TTL | Low TTL of 21 seconds provides quick propagation but may increase DNS load. |
Multiple IPv6 addresses configured for redundancy and load balancing
2a04:4e42:400::7732a04:4e42:200::7732a04:4e42::7732a04:4e42:600::773| Status | Test name | Information |
|---|---|---|
IPv6 Configuration | IPv6 ConfigurationMultiple IPv6 addresses configured for redundancy and load balancing IPv6 Addresses 2a04:4e42:400::7732a04:4e42:200::7732a04:4e42::7732a04:4e42:600::773TTL: 300s Provides a good balance between propagation speed and DNS load |
| Priority | Mail Server | Actions |
|---|---|---|
10 | cnn-com.mail.protection.outlook.com |
| Status | Test name | Information | ||||||
|---|---|---|---|---|---|---|---|---|
Mail Server Consistency | All nameservers are reporting the same mail server configuration. This consistency ensures reliable email delivery. | |||||||
Mail Server Configuration | Mail Exchange Configuration
| |||||||
Mail Server Hostname Validation | All mail server hostnames are properly formatted. | |||||||
Public IP Validation | All mail servers use public IP addresses, ensuring global email delivery. | |||||||
CNAME Validation | Mail servers are properly configured without CNAME records. | |||||||
IP Uniqueness | Each mail server has unique IP addresses, indicating proper distribution of mail handling. | |||||||
Reverse DNS Records | Using managed mail services: Microsoft 365. PTR records are automatically managed by these providers. |
WWW record type: CNAME
199.232.91.52a04:4e42:b::773| Status | Test name | Information |
|---|---|---|
WWW Configuration | WWW record type: CNAME www. CNAME Record cnn-tls.map.fastly.net Resolves To IPv4 Resolution 199.232.91.5IPv6 Resolution 2a04:4e42:b::773 |
| Status | Test name | Information |
|---|---|---|
DNSSEC | This domain uses Amazon Route 53. DNSSEC queries returned SERVFAIL, which may be due to resolver compatibility rather than a configuration issue. Amazon Route 53 manages DNSSEC through their infrastructure โ check their dashboard for DNSSEC status. | |
Zone Transfer | Your domain uses Amazon Route 53 nameservers. AWS Route 53 handles zone transfers through their own secure mechanisms. AXFR responses are part of their managed DNS infrastructure.
Learn more: https://dnschkr.com/blog/dns-attacks-guide#dns-zone-transfer-attack-axfr | |
CAA Records | No CAA records found. While optional, CAA records help control which Certificate Authorities can issue certificates for your domain. | |
Subdomain Takeover | Checked 8 common subdomains. Found 2 CNAME records โ all targets resolve correctly. No dangling CNAME risk detected.
Learn more: https://dnschkr.com/blog/dns-attacks-guide#subdomain-takeover |
stripe-verification | 094254c9a60a6dc0c1c2a62294b81c0c3b9363d044151a3e562ffeac0a7c4157 |
MS | ms66433104 |
_globalsign-domain-verification | -lBuNJDFRxDkLkNbYOLBU03PlWjnPqAzBPAVUokhAw |
MS | ms66433104 |
google-site-verification | _QivaXNjhXy-V1y_YqrycXdAWZi2mVrcwbXerX6THeY |
facebook-domain-verification | xszi21kow2trmw3xt3ph6s631zyu3i |
| Status | Test name | Information | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|
TXT Records | Click any row to copy the raw value
Showing 3 of 61 records (limited view) | |||||||||
SPF Record | Found SPF record: v=spf1 include:cnn.com._nspf.vali.email include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email include:mail.zendesk.com ~all
Invalid include domains found: %{i}._ip.%{h}._ehlo.%{d}._spf.vali.email.
These domains do not conform to valid domain name format requirements. | |||||||||
DMARC Record | Found DMARC record: v=DMARC1; p=reject; rua=mailto:[email protected]; ruf=mailto:[email protected] | |||||||||
Domain Verification | Click any row to copy the raw value
Showing 3 of 7 records (limited view) |