Connectivity: 100%
The following nameservers are available and responding correctly for DNS queries for your domain sagorski.org.
Nameserver | IP address(es) | SOA serial |
---|---|---|
charles.ns.cloudflare.com. |
108.162.193.83
2606:4700:58::adf5:3b53 |
2336428689 |
mia.ns.cloudflare.com. |
108.162.192.200
2606:4700:50::adf5:3ac8 |
2336428689 |
Good news, no warnings or errors were found.
We could not find any recommendations at this time.
Good news, we detected the following achievements in your DNS configuration. Each of these checks has increased your DNS Spy score.
- All nameservers reply with the same SOA serial number.
- The nameserver IPs are distributed across multiple subnets.
- All nameservers are online.
- Nameservers are available over IPv4.
- Nameservers are available over IPv6.
Performance: 100%
We tested each nameserver and measured the following response times.
Nameserver | IP address(es) | Response time |
---|---|---|
charles.ns.cloudflare.com. |
108.162.193.83
2606:4700:58::adf5:3b53 |
1ms
1ms |
mia.ns.cloudflare.com. |
108.162.192.200
2606:4700:50::adf5:3ac8 |
3ms
1ms |
Good news, no warnings or errors were found.
We could not find any recommendations at this time.
Good news, we detected the following achievements in your DNS configuration. Each of these checks has increased your DNS Spy score.
- Nameserver charles.ns.cloudflare.com. (108.162.193.83) replied quickly (< 50ms).
- Nameserver charles.ns.cloudflare.com. (2606:4700:58::adf5:3b53) replied in a reasonable time.
- Nameserver mia.ns.cloudflare.com. (108.162.192.200) replied quickly (< 50ms).
- Nameserver mia.ns.cloudflare.com. (2606:4700:50::adf5:3ac8) replied in a reasonable time.
Resilience & Security: 50%
These are the locations and providers of your nameservers.
Nameserver | Location | ISP |
---|---|---|
charles.ns.cloudflare.com. |
IPv4: US
IPv6: US |
AS13335 - CLOUDFLARENET, US
AS13335 - CLOUDFLARENET, US |
mia.ns.cloudflare.com. |
IPv4: US
IPv6: US |
AS13335 - CLOUDFLARENET, US
AS13335 - CLOUDFLARENET, US |
We detected the following errors or warnings about your DNS configuration. These caused your DNS rating to be lowered. Resolving these will grant a higher DNS Spy rating for your domain.
- All IPv4 nameservers are hosted by the same provider (AS13335 - CLOUDFLARENET, US). Consider spreading the nameservers across multiple DNS providers for increased redundancy.
- All IPv6 nameservers are hosted by the same provider (AS13335 - CLOUDFLARENET, US). Consider spreading the nameservers across multiple DNS providers for increased redundancy.
- All the nameservers are being operated from a single domain (cloudflare.com). If that domain gets compromised or goes offline, the DNS will be unavailable. Consider spreading the nameservers across multiple domains.
We detected some possible recommendations for you to consider. No penalties were given for these, but resolving them can give you a higher DNS score.
- All IPv4 nameservers appear to be hosted in the same country (US). You might want to consider spreading the nameservers geographically.
- All IPv6 nameservers appear to be hosted in the same country (US). You might want to consider spreading the nameservers geographically.
Good news, we detected the following achievements in your DNS configuration. Each of these checks has increased your DNS Spy score.
- You have more than 1 nameserver.
- DNSSEC is enabled.
- CAA records found.
DNS records: 95%
Our scans detected the following publicly available DNS records.
Record | TTL | Value | |
---|---|---|---|
A | sagorski.org | 5m |
185.199.108.153 185.199.109.153 185.199.110.153 185.199.111.153 |
AAAA | sagorski.org | 5m |
2606:50c0:8000::153 2606:50c0:8001::153 2606:50c0:8002::153 2606:50c0:8003::153 |
CAA | sagorski.org | 5m |
0 iodef "mailto:[email protected]" 0 issue "comodoca.com" 0 issue "digicert.com; cansignhttpexchanges=yes" 0 issue "letsencrypt.org" 0 issue "pki.goog; cansignhttpexchanges=yes" 0 issuewild "comodoca.com" 0 issuewild "digicert.com; cansignhttpexchanges=yes" 0 issuewild "letsencrypt.org" 0 issuewild "pki.goog; cansignhttpexchanges=yes" |
DNSKEY | sagorski.org | 1h |
ZSK | ECDSA Curve P-256 with SHA-256 | oJMRESz5E4gYzS/q6XDrvU1qMPYIjCWzJaOau8XNEZeqCYKD5ar0IRd8 KqXXFJkqmVfRvMGPmM1x8fGAa2XhSA== KSK | ECDSA Curve P-256 with SHA-256 | mdsswUyr3DPW132mOi8V9xESWE8jTo0dxCjjnopKl+GqJxpVXckHAeF+ KkxLbxILfDLUT0rAK9iUzy1L53eKGQ== |
MX | sagorski.org | 5m |
10 mxext1.mailbox.org. 20 mxext3.mailbox.org. 9 mxext2.mailbox.org. |
NS | sagorski.org | 24h |
charles.ns.cloudflare.com. mia.ns.cloudflare.com. |
SOA | sagorski.org | 1800s | charles.ns.cloudflare.com. dns.cloudflare.com. 2336428689 10000 2400 604800 1800 |
TXT | sagorski.org | 5m |
"apple-domain=iyXl6baw9dAJNOvF" "google-site-verification=vPokYpBRX8VcOLeP2TRlszejvbiGhwcoYQW5TKWcZqA" "have-i-been-pwned-verification=84a2f678cd37113967856bb8668c9ea7" "sophos-domain-verification=65879babc27fbfe20dac479e6c93e28601653f65079761e9da4b1373a82e4a62" "t-verify=4c5a3104e7bb254ec6fb1c22ed6c296e" "v=spf1 include:mailbox.org ~all" |
SRV | _autodiscover._tcp.sagorski.org | 5m | 0 0 443 mailbox.org. |
TXT | _dmarc.sagorski.org | 5m | "v=DMARC1; p=quarantine; rua=mailto:[email protected]" |
CNAME | autodiscover.sagorski.org | 5m | mailbox.org. |
A | host.sagorski.org | 5m | 138.68.96.29 |
AAAA | host.sagorski.org | 5m | 2a03:b0c0:3:d0::1475:2001 |
CNAME | mirror.sagorski.org | 5m | tor.sagorski.org. |
CNAME | www.sagorski.org | 5m | sagorski.org. |
We detected the following errors or warnings about your DNS configuration. These caused your DNS rating to be lowered. Resolving these will grant a higher DNS Spy rating for your domain.
- Consider giving the MX record for "sagorski.org" a longer TTL, as those don't change often (1h+).
We could not find any recommendations at this time.
Good news, we detected the following achievements in your DNS configuration. Each of these checks has increased your DNS Spy score.
- The root DNS records points to multiple IPs using Round Robin.
- Multiple MX records found.
- MX records with different priorities found (main + fall-back mailservers).
- The MX records points to multiple mailservers.
- The NS records have a long TTL (1h+).
- Your SOA serial number follows the best practice YYYYMMDDxx format.
- SPF records have been found.
- SPF records are set up restrictively.
- DMARC records have been found.
- DMARC records are set up restrictively.
- Found a root (apex) DNS record.
- Found a www DNS record.
- Found an IPv6 root DNS record.
- This domain is Have I Been Pwned? verified, bonus points are awarded for being security conscious.
- The active nameservers match the NS records.
- The DNS records appear to be RFC compliant.
Have a look at other public DNS scans.