DNS report for nic.cn

This report was generated 2 weeks ago. Refresh?
B
Connectivity
100%
Performance
92%
Resilience & Security
60%
DNS records
100%
Proud of your DNS score? Share it with the world!

Connectivity: 100%

The following nameservers are available and responding correctly for DNS queries for your domain nic.cn.

Nameserver IP address(es) SOA serial
a.cnnic.cn. 203.119.25.5
2001:dc7::5
2015021102
b.cnnic.cn. 203.119.26.5
2001:dc7:1::5
2015021102
c.cnnic.cn. 203.119.27.5
2001:dc7:2::5
2015021102
d.cnnic.cn. 203.119.28.5
2001:dc7:1000::5
2015021102
e.cnnic.cn. 203.119.29.5
2001:dc7:3::5
2015021102

Good news, no warnings or errors were found.

We could not find any recommendations at this time.

Good news, we detected the following achievements in your DNS configuration. Each of these checks has increased your DNS Spy score.

  • All nameservers reply with the same SOA serial number.
  • The nameserver IPs are distributed across multiple subnets.
  • All nameservers are online.
  • Nameservers are available over IPv4.
  • Nameservers are available over IPv6.

Performance: 92%

We tested each nameserver and measured the following response times.

Nameserver IP address(es) Response time
a.cnnic.cn. 203.119.25.5
2001:dc7::5
183ms
59ms
b.cnnic.cn. 203.119.26.5
2001:dc7:1::5
39ms
39ms
c.cnnic.cn. 203.119.27.5
2001:dc7:2::5
47ms
39ms
d.cnnic.cn. 203.119.28.5
2001:dc7:1000::5
39ms
55ms
e.cnnic.cn. 203.119.29.5
2001:dc7:3::5
59ms
59ms

We detected the following errors or warnings about your DNS configuration. These caused your DNS rating to be lowered. Resolving these will grant a higher DNS Spy rating for your domain.

  • Nameserver a.cnnic.cn. (203.119.25.5) replied, but took too long (183ms). This will severely impact performance.

We detected some possible recommendations for you to consider. No penalties were given for these, but resolving them can give you a higher DNS score.

  • Nameserver e.cnnic.cn. (203.119.29.5) replied reasonably fast (< 150ms), but you should aim for < 50ms response times.

Good news, we detected the following achievements in your DNS configuration. Each of these checks has increased your DNS Spy score.

  • Nameserver a.cnnic.cn. (2001:dc7::5) replied in a reasonable time.
  • Nameserver b.cnnic.cn. (203.119.26.5) replied quickly (< 50ms).
  • Nameserver b.cnnic.cn. (2001:dc7:1::5) replied in a reasonable time.
  • Nameserver c.cnnic.cn. (203.119.27.5) replied quickly (< 50ms).
  • Nameserver c.cnnic.cn. (2001:dc7:2::5) replied in a reasonable time.
  • Nameserver d.cnnic.cn. (203.119.28.5) replied quickly (< 50ms).
  • Nameserver d.cnnic.cn. (2001:dc7:1000::5) replied in a reasonable time.
  • Nameserver e.cnnic.cn. (2001:dc7:3::5) replied in a reasonable time.

Resilience & Security: 60%

These are the locations and providers of your nameservers.

Nameserver Location ISP
a.cnnic.cn. IPv4: CN
IPv6: CN
AS24151 - CNNIC-CRITICAL-AP China Internet Network Infomation Center, CN
AS24406 24409 -
b.cnnic.cn. IPv4: CN
IPv6: CN
AS24151 24406 -
AS24406 - CNNIC-CRITICAL-AP China Internet Network Infomation Center, CN
c.cnnic.cn. IPv4: CN
IPv6: CN
AS24406 24409 -
AS24406 24409 -
d.cnnic.cn. IPv4: CN
IPv6: CN
AS24151 24406 -
AS24406 24409 -
e.cnnic.cn. IPv4: CN
IPv6: CN
AS24151 24406 -
AS24406 - CNNIC-CRITICAL-AP China Internet Network Infomation Center, CN

We detected the following errors or warnings about your DNS configuration. These caused your DNS rating to be lowered. Resolving these will grant a higher DNS Spy rating for your domain.

  • No DNSSEC records found. Consider enabling DNSSEC, as it provides a way to validate DNS responses for data integrity.
  • All the nameservers are being operated from a single domain (cnnic.cn). If that domain gets compromised or goes offline, the DNS will be unavailable. Consider spreading the nameservers across multiple domains.

We detected some possible recommendations for you to consider. No penalties were given for these, but resolving them can give you a higher DNS score.

  • All IPv4 nameservers appear to be hosted in the same country (CN). You might want to consider spreading the nameservers geographically.
  • All IPv6 nameservers appear to be hosted in the same country (CN). You might want to consider spreading the nameservers geographically.
  • No CAA records found. Consider adding CAA records, as it adds increased security by limiting which Certificate Authorities can issue certificates for this domain. (more info)

Good news, we detected the following achievements in your DNS configuration. Each of these checks has increased your DNS Spy score.

  • You have more than 1 nameserver.
  • The IPv4 nameservers are distributed among multiple providers.
  • The IPv6 nameservers are distributed among multiple providers.

DNS records: 100%

Our scans detected the following publicly available DNS records.

Record TTL Value
A nic.cn 24h 10.10.10.10
NS nic.cn 24h a.cnnic.cn.
b.cnnic.cn.
c.cnnic.cn.
d.cnnic.cn.
e.cnnic.cn.
SOA nic.cn 24h a.cnnic.cn. sun.nic.cn. 2015021102 10800 3600 604800 86400
A a.cnnic.cn..nic.cn 600s 203.119.25.5
A c.cnnic.cn..nic.cn 600s 203.119.27.5
A d.cnnic.cn..nic.cn 600s 203.119.28.5
A e.cnnic.cn..nic.cn 600s 203.119.29.5

Good news, no warnings or errors were found.

We detected some possible recommendations for you to consider. No penalties were given for these, but resolving them can give you a higher DNS score.

  • No SPF records were found. SPF records limit which IPs are allowed to send mail from this domain. Even if this domain doesn't send e-mails, you should set up SPF to confirm it will never send e-mail, to prevent spoofing.
  • No DMARC records have been found. Consider configuring DMARC for improved e-mail authentication.
  • No IPv6 record has been found on the zone apex (nic.cn). Consider enabling IPv6 in the infrastructure by adding an AAAA record on this domain.

Good news, we detected the following achievements in your DNS configuration. Each of these checks has increased your DNS Spy score.

  • The NS records have a long TTL (1h+).
  • Your SOA serial number follows the best practice YYYYMMDDxx format.
  • Found a root (apex) DNS record.
  • The active nameservers match the NS records.
  • The DNS records appear to be RFC compliant.
Proud of your DNS score? Share it with the world!

 

Have a look at other public DNS scans.