Total Tests
40
Passed
31
Critical Issues
1
Information provided by j.gtld-servers.net
194.169.218.362001:67c:13cc::1:36185.24.64.362a04:2b00:13cc::1:36212.18.248.362a04:2b00:13ee::36212.18.249.362a04:2b00:13ff::36Note:
Glue records are required for these nameservers since they are under your domain. This prevents circular dependencies in DNS resolution.
| Status | Test name | Information |
|---|---|---|
Authoritative Nameservers | These nameservers are responsible for answering queries about your domain 4 Records ns1.nic.co.comns2.nic.co.comns3.nic.co.comns4.nic.co.comSource: This information was kindly provided by j.gtld-servers.net ๐๐ผ | |
TLD Delegation Check | Good. j.gtld-servers.net has information for your TLD. This confirms your domain is properly delegated. | |
Nameservers Listed at Parent | Good. The parent server has your nameservers listed and they match the actual NS records. This ensures consistent DNS resolution. | |
Glue Records from Parent | Glue Records from Parent ServerInformation provided by j.gtld-servers.net ns1.nic.co.comNameserver IPv4 Addresses: 194.169.218.36IPv6 Addresses: 2001:67c:13cc::1:36ns2.nic.co.comNameserver IPv4 Addresses: 185.24.64.36IPv6 Addresses: 2a04:2b00:13cc::1:36ns3.nic.co.comNameserver IPv4 Addresses: 212.18.248.36IPv6 Addresses: 2a04:2b00:13ee::36ns4.nic.co.comNameserver IPv4 Addresses: 212.18.249.36IPv6 Addresses: 2a04:2b00:13ff::36Note: Glue records are required for these nameservers since they are under your domain. This prevents circular dependencies in DNS resolution. |
| Status | Test name | Information |
|---|---|---|
Nameserver Records from Zone | ns3.nic.co.comIPv4 Addresses 212.18.248.36 IPv6 Addresses 2a04:2b00:13ee::36 Authoritative Non-Recursive TCP UDP TTL: 172,800s (2 days) ns4.nic.co.comIPv4 Addresses 212.18.249.36 IPv6 Addresses 2a04:2b00:13ff::36 Authoritative Non-Recursive TCP UDP TTL: 172,800s (2 days) ns2.nic.co.comIPv4 Addresses 185.24.64.36 IPv6 Addresses 2a04:2b00:13cc::1:36 Authoritative Non-Recursive TCP UDP TTL: 172,800s (2 days) ns1.nic.co.comIPv4 Addresses 194.169.218.36 IPv6 Addresses 2001:67c:13cc::1:36 Authoritative Non-Recursive TCP UDP TTL: 172,800s (2 days) | |
Open Recursive Queries | Good. No nameservers allow recursive queries. | |
Glue Record Consistency | The GLUE records from the parent zone match those from your nameservers. This is important for consistent DNS resolution. | |
Missing Glue for NS Records | Note: Your nameservers are not under your domain, so additional glue records are not required. | |
Mismatched NS records | Good. The NS records at all your nameservers are identical. | |
DNS servers responded | Good. All nameservers listed at the parent server responded. | |
Name of nameservers are valid | All NS records appear to be valid hostnames. | |
Nameserver Redundancy Check | You have 4 nameservers. This meets the minimum requirement, though RFC2182 section 5 recommends at least 3 for better reliability. | |
Lame Delegation Check | Good. All nameservers are answering authoritatively for your domain. | |
Parent Missing Nameservers | Good. All NS records match between parent and nameservers, as required by RFC1034 section 3.6. | |
Zone Missing Nameservers | Good. All parent-listed nameservers are reported by your nameservers, as required by RFC1034 section 3.6. | |
CNAMEs at Apex Check | Good. No CNAME records found for NS records, as per RFC1912 section 2.4 and RFC2181 section 10.3. | |
NS IP Subnet Diversity | Found 1 pair(s) of nameserver IPs in the same /16 subnet. For better redundancy, consider using nameservers on different subnets as recommended by RFC2182 section 5. Affected pairs: 212.18.248.36 and 212.18.249.36. Note: providers using anycast may have geographic redundancy despite shared subnets. | |
NS IP Public Accessibility | Good. All nameserver IPs (both IPv4 and IPv6) are public, ensuring global accessibility as required by RFC1035. | |
DNS servers allow TCP connection | Good. All DNS servers allow TCP connections, which is required for larger DNS responses as per RFC1035. | |
DNS servers allow UDP connection | Good. All DNS servers allow UDP connections, which is required for standard DNS queries. | |
NS AS Diversity Check | Good. Your nameservers appear to be on different networks, providing better redundancy. | |
Stealth Nameserver Check | Good. All nameservers in your zone are properly registered at the parent. This ensures consistent DNS resolution for all users. |
Serial Number
2014408867
A unique version number that changes whenever the zone file is updated
How often secondary nameservers check for updates (20m - 24h)
How long to wait before retrying a failed zone transfer (2m - 2h)
How long secondary servers serve stale zone data (1w - 4w)
Default time-to-live for resource records (5m - 24h)
| Status | Test name | Information |
|---|---|---|
SOA record | Primary Nameserverns0.nic.co.com Hostmaster Emailhostmaster.co.com Serial Number 2014408867 Non-Standard (Unix Timestamp) A unique version number that changes whenever the zone file is updated Time IntervalsRefresh900 seconds (15 minutes) How often secondary nameservers check for updates (20m - 24h) Retry1800 seconds (30 minutes) How long to wait before retrying a failed zone transfer (2m - 2h) Expire6048000 seconds (70 days) How long secondary servers serve stale zone data (1w - 4w) TTL3600 seconds (1 hours) Default time-to-live for resource records (5m - 24h) | |
SOA Serial Consistency | SOA Serial numbers per nameserver:
ns3.nic.co.com: 2014408867
ns4.nic.co.com: 2014408867
ns2.nic.co.com: 2014408867
ns1.nic.co.com: 2014408867
Good. All nameservers report the same SOA serial number. | |
SOA MNAME entry | Warning: Primary nameserver ns0.nic.co.com is not listed in your NS records. MNAME doesn't match a member of the NS RRSET. This is OK but may be problematic with zones using Dynamic Updates. | |
SOA Serial | Your SOA serial number is: 2014408867. | |
SOA REFRESH | Warning: SOA REFRESH interval is 900 seconds (15 minutes). This is below the recommended minimum of 1200 seconds as per RFC1912 section 2.2. | |
SOA RETRY | Warning: SOA RETRY value (1800 seconds) is higher than refresh (900 seconds). According to RFC1912 section 2.2, retry should be less than refresh to prevent unnecessary zone transfer attempts. | |
SOA EXPIRE | Current expire time is 6048000 seconds (70 days).
Warning: Common practice recommends a maximum of 28 days (2419200 seconds) to avoid stale data being served for too long. | |
SOA MINIMUM TTL | OK. Your SOA MINIMUM TTL is: 3600 seconds (60 minutes). This value is used for negative caching and is within the recommended range of 180-86400 seconds as per RFC2308 section 4. |
Single IPv4 address configuration
169.60.151.232| Status | Test name | Information |
|---|---|---|
A Record Configuration | IPv4 ConfigurationSingle IPv4 address configuration IPv4 Addresses 169.60.151.232TTL: 300s Provides a good balance between propagation speed and DNS load | |
A Record TTL | TTL of 300 seconds provides a good balance between propagation speed and DNS load. |
| Status | Test name | Information |
|---|---|---|
IPv6 Support | No AAAA (IPv6) records found. While not required, IPv6 support is recommended for future-proofing your domain and improving accessibility for IPv6 users. |
| Priority | Mail Server | Actions |
|---|---|---|
10 | mx.spamexperts.com | |
20 | fallbackmx.spamexperts.eu | |
30 | lastmx.spamexperts.net |
| PTR Query | Hostname |
|---|---|
150.250.101.38.in-addr.arpa | fe3-r2-in.atl06.l.antispamcloud.com |
156.254.89.38.in-addr.arpa | fe1-r2-in.ch03.l.antispamcloud.com |
244.16.71.38.in-addr.arpa | fe2-r2-in.la10.l.antispamcloud.com |
150.250.101.38.in-addr.arpa | fe3-r2-in.atl06.l.antispamcloud.com |
244.16.71.38.in-addr.arpa | fe2-r2-in.la10.l.antispamcloud.com |
27.75.13.149.in-addr.arpa | fe1-r3-in.fra02.l.antispamcloud.com |
23.104.59.154.in-addr.arpa | fe2-r3-in.ams14.l.antispamcloud.com |
156.254.89.38.in-addr.arpa | fe1-r2-in.ch03.l.antispamcloud.com |
| Status | Test name | Information | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Mail Server Consistency | All nameservers are reporting the same mail server configuration. This consistency ensures reliable email delivery. | |||||||||||||||||||
Mail Server Configuration | Mail Exchange Configuration
| |||||||||||||||||||
Mail Server Hostname Validation | All mail server hostnames are properly formatted. | |||||||||||||||||||
Public IP Validation | All mail servers use public IP addresses, ensuring global email delivery. | |||||||||||||||||||
CNAME Validation | Mail servers are properly configured without CNAME records. | |||||||||||||||||||
IP Uniqueness | Warning: The following IP addresses are shared between multiple mail servers:
38.101.250.150 is shared by: mx.spamexperts.com, fallbackmx.spamexperts.eu
38.89.254.156 is shared by: fallbackmx.spamexperts.eu, lastmx.spamexperts.net
38.71.16.244 is shared by: fallbackmx.spamexperts.eu, lastmx.spamexperts.net
This may indicate suboptimal mail handling distribution. | |||||||||||||||||||
Reverse DNS Records | Reverse DNS RecordsAll Valid
Proper reverse DNS records are essential for email deliverability. Mail servers often check if sending IPs have matching PTR records. |
WWW record type: A
173.192.76.171Recommendation
Consider using a CNAME record for better flexibility
| Status | Test name | Information |
|---|---|---|
WWW Configuration | WWW record type: A www. A Record IPv4 Addresses 173.192.76.171Recommendation Consider using a CNAME record for better flexibility |
| Status | Test name | Information |
|---|---|---|
DNSSEC | DNSSEC validation failed. This indicates a problem with your DNSSEC configuration:
โข DNSKEY query failed with SERVFAIL
โข DS query failed with SERVFAIL
Please check your DNSSEC configuration with your DNS provider. | |
Zone Transfer | Zone transfer (AXFR) is properly restricted. Tested 4 nameservers โ all refused the transfer request.
Learn more: https://dnschkr.com/blog/dns-attacks-guide#dns-zone-transfer-attack-axfr | |
Wildcard DNS | Warning: Wildcard DNS records found. This means any subdomain will resolve to an IP address, which could pose security risks. | |
NXDOMAIN Response | Warning: Server does not return NXDOMAIN for non-existent domains. This could indicate misconfiguration or intentional wildcard records. | |
CAA Records | No CAA records found. While optional, CAA records help control which Certificate Authorities can issue certificates for your domain. | |
Subdomain Takeover | Checked 8 common subdomains โ none have external CNAME records. No subdomain takeover risk from dangling CNAMEs.
Learn more: https://dnschkr.com/blog/dns-attacks-guide#subdomain-takeover |
v | spf1 mx ip4:169.60.151.232 ip4:184.172.61.109 ip4:169.60.163.139 ip4:169.60.135.222 a:codotcom.kayako.com include:servers.mcsv.net -all |
google-site-verification | 7OcubotXUUSYYCSil8JjPJ_2uxorUHKIpmbUGsV_caA |
google-site-verification | 7OcubotXUUSYYCSil8JjPJ_2uxorUHKIpmbUGsV_caA |
| Status | Test name | Information | ||||||
|---|---|---|---|---|---|---|---|---|
TXT Records | Click any row to copy the raw value
Showing 2 of 2 records | |||||||
SPF Record | Found SPF record: v=spf1 mx ip4:169.60.151.232 ip4:184.172.61.109 ip4:169.60.163.139 ip4:169.60.135.222 a:codotcom.kayako.com include:servers.mcsv.net -all | |||||||
DMARC Record | Found DMARC record: v=DMARC1; p=quarantine; sp=none; rua=mailto:[email protected] | |||||||
Domain Verification | Click any row to copy the raw value
Showing 1 of 1 record |