DNS Records for
packpremium70.me
๐ Hunting for rogue glue records.
Total Tests
27
Passed
23
Critical Issues
1
Information provided by b2.nic.me
162.159.27.158162.159.26.922400:cb00:2049:1::a29f:1a5c2400:cb00:2049:1::a29f:1b9e162.159.24.5162.159.25.52400:cb00:2049:1::a29f:19052400:cb00:2049:1::a29f:1805Note:
The parent server is providing glue records for these nameservers. While not required (since the nameservers are not under your domain), this helps optimize DNS resolution.
| Status | Test name | Information |
|---|---|---|
Authoritative Nameservers | These nameservers are responsible for answering queries about your domain 2 Records ns1.dyna-ns.netns2.dyna-ns.netSource: This information was kindly provided by b2.nic.me ๐๐ผ | |
TLD Delegation Check | Good. b2.nic.me has information for your TLD. This confirms your domain is properly delegated. | |
Nameservers Listed at Parent | Good. The parent server has your nameservers listed and they match the actual NS records. This ensures consistent DNS resolution. | |
Glue Records from Parent | Glue Records from Parent ServerInformation provided by b2.nic.me ns1.dyna-ns.netNameserver IPv4 Addresses: 162.159.27.158162.159.26.92IPv6 Addresses: 2400:cb00:2049:1::a29f:1a5c2400:cb00:2049:1::a29f:1b9ens2.dyna-ns.netNameserver IPv4 Addresses: 162.159.24.5162.159.25.5IPv6 Addresses: 2400:cb00:2049:1::a29f:19052400:cb00:2049:1::a29f:1805Note: The parent server is providing glue records for these nameservers. While not required (since the nameservers are not under your domain), this helps optimize DNS resolution. |
| Status | Test name | Information |
|---|---|---|
Nameserver Records from Zone | ns2.dyna-ns.netIPv4 Addresses 162.159.25.5 162.159.24.5 IPv6 Addresses 2400:cb00:2049:1::a29f:1805 2400:cb00:2049:1::a29f:1905 Authoritative Non-Recursive TCP UDP TTL: 3,600s (0 days) ns1.dyna-ns.netIPv4 Addresses 162.159.27.158 162.159.26.92 IPv6 Addresses 2400:cb00:2049:1::a29f:1a5c 2400:cb00:2049:1::a29f:1b9e Authoritative Non-Recursive TCP UDP TTL: 3,600s (0 days) | |
Open Recursive Queries | Good. No nameservers allow recursive queries. | |
Glue Record Consistency | The GLUE records from the parent zone match those from your nameservers. This is important for consistent DNS resolution. | |
Missing Glue for NS Records | Note: Your nameservers are not under your domain, so additional glue records are not required. | |
Mismatched NS records | Good. The NS records at all your nameservers are identical. | |
DNS servers responded | Good. All nameservers listed at the parent server responded. | |
Name of nameservers are valid | All NS records appear to be valid hostnames. | |
Nameserver Redundancy Check | You have 2 nameservers. This meets the minimum requirement, though RFC2182 section 5 recommends at least 3 for better reliability. | |
Lame Delegation Check | Good. All nameservers are answering authoritatively for your domain. | |
Parent Missing Nameservers | Good. All NS records match between parent and nameservers, as required by RFC1034 section 3.6. | |
Zone Missing Nameservers | Good. All parent-listed nameservers are reported by your nameservers, as required by RFC1034 section 3.6. | |
CNAMEs at Apex Check | Good. No CNAME records found for NS records, as per RFC1912 section 2.4 and RFC2181 section 10.3. | |
NS IP Subnet Diversity | Found 6 pair(s) of nameserver IPs in the same /16 subnet. For better redundancy, consider using nameservers on different subnets as recommended by RFC2182 section 5. Affected pairs: 162.159.25.5 and 162.159.24.5, 162.159.25.5 and 162.159.27.158, 162.159.25.5 and 162.159.26.92, 162.159.24.5 and 162.159.27.158, 162.159.24.5 and 162.159.26.92, 162.159.27.158 and 162.159.26.92. Note: providers using anycast may have geographic redundancy despite shared subnets. | |
NS IP Public Accessibility | Good. All nameserver IPs (both IPv4 and IPv6) are public, ensuring global accessibility as required by RFC1035. | |
DNS servers allow TCP connection | Good. All DNS servers allow TCP connections, which is required for larger DNS responses as per RFC1035. | |
DNS servers allow UDP connection | Good. All DNS servers allow UDP connections, which is required for standard DNS queries. | |
NS AS Diversity Check | Good. Your nameservers appear to be on different networks, providing better redundancy. | |
Stealth Nameserver Check | Good. All nameservers in your zone are properly registered at the parent. This ensures consistent DNS resolution for all users. |
| Status | Test name | Information |
|---|---|---|
SOA Record | No SOA record found. Every domain should have an SOA record. |
Single IPv4 address configuration
31.57.111.120| Status | Test name | Information |
|---|---|---|
A Record Configuration | IPv4 ConfigurationSingle IPv4 address configuration IPv4 Addresses 31.57.111.120TTL: 300s Provides a good balance between propagation speed and DNS load | |
A Record TTL | TTL of 300 seconds provides a good balance between propagation speed and DNS load. |
| Status | Test name | Information |
|---|---|---|
IPv6 Support | No AAAA (IPv6) records found. While not required, IPv6 support is recommended for future-proofing your domain and improving accessibility for IPv6 users. |
| Status | Test name | Information |
|---|---|---|
Mail Server Configuration | No MX records found. Email delivery will fall back to the domain's A record. |
| Status | Test name | Information |
|---|---|---|
WWW Configuration | No WWW record found |
| Status | Test name | Information |
|---|---|---|
DNSSEC | DNSSEC validation failed. This indicates a problem with your DNSSEC configuration:
โข DNSKEY query failed with SERVFAIL
โข DS query failed with SERVFAIL
Please check your DNSSEC configuration with your DNS provider. | |
Zone Transfer | Zone transfer (AXFR) is properly restricted. Tested 2 nameservers โ all refused the transfer request.
Learn more: https://dnschkr.com/blog/dns-attacks-guide#dns-zone-transfer-attack-axfr | |
Wildcard DNS | Good. Tested notrealdnschkr.packpremium70.me - No wildcard DNS records found, ensuring random subdomains won't resolve to an IP address. | |
NXDOMAIN Response | Warning: Server does not return NXDOMAIN for non-existent domains. This could indicate misconfiguration or intentional wildcard records. | |
CAA Records | No CAA records found. While optional, CAA records help control which Certificate Authorities can issue certificates for your domain. | |
Subdomain Takeover | Checked 8 common subdomains โ none have external CNAME records. No subdomain takeover risk from dangling CNAMEs.
Learn more: https://dnschkr.com/blog/dns-attacks-guide#subdomain-takeover |
| Status | Test name | Information |
|---|---|---|
TXT Records | No TXT records found at the apex (@) of this domain. TXT records may still exist on subdomains (e.g., _dmarc, _domainkey selectors). |