Category | Status | Test name | Information send feedback |
---|---|---|---|
Parent | Domain NS records | Nameserver records returned by the parent servers are: shaven.yak.net. ['138.68.10.128'] [TTL=172800] fifth.yak.net. ['192.241.138.186'] [TTL=172800] lid1.zhuk.com. [] (NO GLUE) [TTL=172800] k.gtld-servers.net was kind enough to give us that information.
| |
TLD Parent Check | Good. k.gtld-servers.net, the parent server I interrogated, has information for your TLD. This is a good thing as there are some other domain extensions like "co.us" for example that are missing a direct check. | ||
Your nameservers are listed | Good. The parent server k.gtld-servers.net has your nameservers listed. This is a must if you want to be found as anyone that does not know your DNS servers will first ask the parent nameservers. | ||
DNS Parent sent Glue | The parent nameserver k.gtld-servers.net is not sending out GLUE for every nameservers listed, meaning he is sending out your nameservers host names without sending the A records of those nameservers. It's ok but you have to know that this will require an extra A lookup that can delay a little the connections to your site. This happens a lot if you have nameservers on different TLD (domain.com for example with nameserver ns.domain.org.) | ||
Nameservers A records | ERROR: Some of your DNS servers do not have A records at all. I could not find any A records for the following DNS servers: lid1.zhuk.com You must have A records for all of your nameservers. |
||
NS | NS records from your nameservers | NS records got from your nameservers listed at the parent NS are: shaven.yak.net ['138.68.10.128'] [TTL=1111] fifth.yak.net ['192.241.138.186'] [TTL=1111] |
|
Recursive Queries | Good. Your nameservers (the ones reported by the parent server) do not report that they allow recursive queries for anyone. | ||
Same Glue | The A records (the GLUE) got from the parent zone check are the same as the ones got from your nameservers. You have to make sure your parent server has the same NS records for your zone as you do according to the RFC. This tests only nameservers that are common at the parent and at your nameservers. If there are any missing or stealth nameservers you should see them below! | ||
Glue for NS records | OK. When I asked your nameservers for your NS records they also returned the A records for the NS records. This is a good thing as it will spare an extra A lookup needed to find those A records. | ||
Mismatched NS records | OK. The NS records at all your nameservers are identical. | ||
DNS servers responded | ERROR: One or more of your nameservers did not respond: The ones that did not respond are: lid1.zhuk.com |
||
Name of nameservers are valid | OK. All of the NS records that your nameservers report seem valid. | ||
Multiple Nameservers | Good. You have multiple nameservers. According to RFC2182 section 5 you must have at least 3 nameservers, and no more than 7. Having 2 nameservers is also ok by me. | ||
Nameservers are lame | OK. All the nameservers listed at the parent servers answer authoritatively for your domain. | ||
Missing nameservers reported by parent | OK. All NS records are the same at the parent and at your nameservers. | ||
Missing nameservers reported by your nameservers | ERROR: One or more of the nameservers listed at the parent servers are not listed as NS records at your nameservers. The problem NS records are:
lid1.zhuk.com This is listed as an ERROR because there are some cases where nasty problems can occur (if the TTLs vary from the NS records at the root servers and the NS records point to your own domain, for example). |
||
Domain CNAMEs | OK. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present. | ||
NSs CNAME check | OK. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present. | ||
Different subnets | OK. Looks like you have nameservers on different subnets! | ||
IPs of nameservers are public | Ok. Looks like the IP addresses of your nameservers are public. This is a good thing because it will prevent DNS delays and other problems like | ||
DNS servers allow TCP connection | OK. Seems all your DNS servers allow TCP connections. This is a good thing and useful even if UDP connections are used by default. | ||
Different autonomous systems | OK. It seems you are safe from a single point of failure. You must be careful about this and try to have nameservers on different locations as it can prevent a lot of problems if one nameserver goes down. | ||
Stealth NS records sent | Ok. No stealth ns records are sent | ||
SOA | SOA record | The SOA record is: Primary nameserver: fifth.yak.net Hostmaster E-mail address: dns.yak.net Serial #: 20240425 Refresh: 600 Retry: 300 Expire: 2592000 4 weeks Default TTL: 900 |
|
NSs have same SOA serial | OK. All your nameservers agree that your SOA serial number is 20240425. | ||
SOA MNAME entry | OK. fifth.yak.net That server is listed at the parent servers. | ||
SOA Serial | Your SOA serial number is: 20240425.
The recommended format (per RFC1912 2.2) is YYYYMMDDnn, where 'nn' is the revision. Your SOA serial appears to be the number of seconds since midnight 01 Jan 1970 when the last DNS change was made. That seems to be 1970/8/23 1:20:25 |
||
SOA REFRESH | WARNING: Your SOA REFRESH interval is: 600. That is not so ok | ||
SOA RETRY | Your SOA RETRY value is: 300. Looks ok | ||
SOA EXPIRE | Your SOA EXPIRE number is: 2592000. That is NOT OK | ||
SOA MINIMUM TTL | Your SOA MINIMUM TTL is: 900. This value was used to serve as a default TTL for records without a given TTL value and now is used for negative caching (indicates how long a resolver may cache the negative answer). RFC2308 recommends a value of 1-3 hours. Your value of 900 is OK. | ||
MX | MX Records | Your MX records that were reported by your nameservers are: 30 aspmx4.googlemail.com 142.250.150.27 (no glue) 20 alt2.aspmx.l.google.com 142.251.9.26 (no glue) 30 aspmx2.googlemail.com 142.250.153.27 (no glue) 20 alt1.aspmx.l.google.com 142.250.153.27 (no glue) 30 aspmx5.googlemail.com 74.125.200.26 (no glue) 30 aspmx3.googlemail.com 142.251.9.26 (no glue) 10 aspmx.l.google.com 74.125.206.27 (no glue) [These are all the MX records that I found. If there are some non common MX records at your nameservers you should see them below. ] |
|
Different MX records at nameservers | Good. Looks like all your nameservers have the same set of MX records. This tests to see if there are any MX records not reported by all your nameservers and also MX records that have the same hostname but different IPs | ||
MX name validity | Good. I did not detect any invalid hostnames for your MX records. | ||
MX IPs are public | OK. All of your MX records appear to use public IPs. | ||
MX CNAME Check | OK. No problems here. | ||
MX A request returns CNAME | OK. No CNAMEs returned for A records lookups. | ||
MX is not IP | OK. All of your MX records are host names. | ||
Number of MX records | Good. Looks like you have multiple MX records at all your nameservers. This is a good thing and will help in preventing loss of mail. | ||
Mismatched MX A | OK. I did not detect differing IPs for your MX records. | ||
Duplicate MX A records | OK. You have some duplicate MX records (MX records with the same IPs). This is not that good but if you know what you are doing than it's ok. | ||
Reverse MX A records (PTR) | Your reverse (PTR) record: 26.9.251.142.in-addr.arpa -> rc-in-f26.1e100.net 27.206.125.74.in-addr.arpa -> wk-in-f27.1e100.net 26.200.125.74.in-addr.arpa -> sa-in-f26.1e100.net 27.153.250.142.in-addr.arpa -> ea-in-f27.1e100.net 27.150.250.142.in-addr.arpa -> la-in-f27.1e100.net You have reverse (PTR) records for all your IPs, that is a good thing. |
||
WWW | WWW A Record |
Your www.yak.net A record is: www.yak.net [159.203.156.162] |
|
IPs are public | OK. All of your WWW IPs appear to be public IPs. | ||
WWW CNAME | OK. No CNAME |
Processed in 0.330 seconds.